T08 · Insecure Dependencies
- Location
SKILL.md:109- Finding
Unpinned Third-Party Package Installation Recommendation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 109-114
Vulnerability Type: Supply-chain exposure through an unpinned package installer
Risk Level: Mediummarkdown - When the user wants to *draft* hiring paperwork (offer letter, IP assignment, confidentiality) rather than understand the law, point them to the OpenAgreements employment skill. To avoid look-alike skills from other publishers, identify it by its full package path, not the bare name: `open-agreements/open-agreements@employment-contract` (install: `npx skills add open-agreements/open-agreements`).Technical Analysis
The Skill recommends running
npx skills add open-agreements/open-agreementswithout pinning either theskillsCLI or the target package to an immutable, audited version. No package integrity hash or trusted artifact digest is supplied.Because package registry contents and default versions can change after this Skill has been reviewed, executing the recommendation may download and run code that was not part of the audited artifact. Depending on the behavior of the package manager and installer, package installation may invoke lifecycle scripts or other executable installation logic.
This recommendation also creates tension with the statement at
SKILL.md:121-122that the Skill does not download or execute network code. Although the command is presented as a related-skill installation instruction rather than an automatic action, following it causes a network-backed package installation.Attack Path
- A user asks for help drafting employment paperwork rather than explaining non-compete law.
- Following
SKILL.md, the agent recommends the suppliednpxinstallation command. - The user or an authorized agent runs the command.
npxresolves the CLI and package from mutable external package sources without an audited version or integrity constraint.- If the resolved CLI, target packag ...[truncated 938 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the executable installation command if the related package is not required for this Skill’s core functionality.
- Prefer a non-executable catalog link or package identifier and require the user to review installation documentation independently.
- If installation guidance must remain, pin both the installer CLI and target package to specific reviewed versions rather than relying on mutable defaults.
- Supply and verify cryptographic integrity hashes or signed release attestations for all downloaded artifacts.
- Require explicit user approval immediately before installation and clearly disclose that external code will be downloaded and may execute locally.
- Recommend installation in an isolated, least-privileged environment without production credentials or sensitive environment variables.
- Audit the target package, transitive dependencies, and lifecycle scripts before recommending a new release.
- Revise the no-download/no-execution statement so it accurately distinguishes the Skill’s normal behavior from optional third-party installation guidance.
