T08 · Insecure Dependencies
- Location
SKILL.md:65- Finding
Unpinned Third-Party Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:65andSKILL.md:69; related dependency import atscripts/eval-skill.py:20
Vulnerability Type: Unpinned third-party dependencies and mutable package execution
Risk Level: MediumVulnerable Code
markdown This evaluator covers security basics (credentials, input validation, data safety) but for thorough security audits of skills under development, consider [SkillLens](https://www.npmjs.com/package/skilllens) (`npx skilllens scan <path>`).markdown - PyYAML (`pip install pyyaml`) — for frontmatter parsing in automated checksThe installed PyYAML package is subsequently loaded by the evaluator:
python import yamlTechnical Analysis
The documented
npx skilllens scan <path>command may retrieve and immediately execute whichever package version the npm registry resolves at invocation time. The instruction does not pin a reviewed version, require a lockfile, verify an integrity hash, or require installation and inspection before execution. Consequently, the effective code can change after this Skill has been audited.The
pip install pyyamlinstruction similarly installs a mutable, unpinned package version. The evaluator imports that package at startup, so package initialization code executes with the evaluator's privileges. The evaluator itself appropriately usesyaml.safe_load; the issue is dependency provenance and version mutability rather than unsafe YAML deserialization.Attack Path
- An attacker compromises a relevant registry account, package release, maintainer environment, or transitive dependency.
- The attacker publishes malicious package content under a version that an unpinned command can resolve.
- A user follows
SKILL.mdand runsnpx skilllens scan <path>or installs unpinned PyYAML. - The package registry supplies mutable third-party code without local integrity verification.
- The downloaded code executes under the inv ...[truncated 793 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin SkillLens to an exact reviewed version:
bash npx --yes skilllens@REVIEWED_VERSION scan /path/to/skill -
Prefer installing dependencies through a committed lockfile and then using
npx --no-installso the scan cannot silently retrieve a different release:bash npm ci npx --no-install skilllens scan /path/to/skill -
Verify npm lockfile integrity and package provenance before execution. Run external scanners in a restricted environment with minimal filesystem access, no unnecessary credentials, and controlled network access.
-
Pin PyYAML to a reviewed version or tightly bounded compatible range. For reproducible installation, use a requirements file with cryptographic hashes:
text PyYAML==REVIEWED_VERSION --hash=sha256:VERIFIED_HASHInstall it with:
bash python3 -m pip install --require-hashes -r requirements.txt -
Clearly label SkillLens as an optional external tool that downloads and executes third-party code, and advise users not to expose unrelated sensitive directories or credentials to the scanning process.
-
