T08 · Insecure Dependencies
- Location
SKILL.md:21- Finding
Unpinned CLI Execution and Unsafeguarded Third-Party Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` `SKILL.md:43-44`: ```bash npx skills find [query] ``` `SKILL.md:55-63`: ```text Install with npx skills add vercel-labs/agent-skills@vercel-react-best-practices └ https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices ``` `SKILL.md:79-84`: ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill directs an agent to invoke `npx skills` without pinning the npm package to a reviewed version or integrity value. Depending on the local npm environment, `npx` can retrieve and execute a package from the configured registry. Consequently, the effective CLI implementation may change after this skill has been audited. The workflow also permits skills to be installed from GitHub or unspecified other sources without requiring: - An allowlist of trusted publishers. - Immutable commit or release pinning. - Signature or integrity verification. - Inspection of the downloaded skill's instructions and scripts. - Review of package lifecycle behavior. - Explicit confirmation immediately before installation. The recommended installation command uses `-g`, extending the installation to the user's global skill environment, and `-y`, suppressing an intera ...[truncated 2634 chars]- Remediation
View remediation
