T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned CLI and Agent Skill Installation Expands the Trusted Supply Chain
- Content
View full analysis
- Remediation
View remediation
``` 2. Enforce package integrity through a lockfile, verified package digest, signed provenance, or an organization-controlled registry mirror. 3. Prefer a project-local installation over a global installation where practical, reducing the affected scope: ```bash npm install --save-dev @insforge/cli@ ``` 4. Do not automatically install Agent Skills as a side effect of project creation. Make this a separate, opt-in operation requiring explicit user approval. 5. Pin the Agent Skill repository to an immutable release or commit and verify its contents before loading it. 6. Display the package version, source, permissions, and intended changes before installation. 7. In CI/CD, install with a restricted service account, a minimal environment, read-only credentials where possible, and disabled unnecessary lifecycle scripts. 8. Re-audit downloaded Agent Skills and dependency updates before accepting newer versions. ]]>
