T08 · Insecure Dependencies
- Location
SKILL.md:288- Finding
Mutable “latest” package versions are downloaded and executed
- Content
View full analysis
- Remediation
View remediation
create ``` 2. Keep the version consistent with the versions declared in the Skill metadata. 3. Review package provenance, publisher identity, release signatures or attestations, and registry integrity before approving updates. 4. Use lockfiles and integrity hashes for subsequent dependency installation. 5. Perform version upgrades through an explicit review process rather than automatically following a mutable distribution tag. 6. Where feasible, run scaffolding tools in an isolated workspace with restricted credentials and no unnecessary secrets in the environment. ]]>
