T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Instapaper CLI guide, with some credential-hygiene and supply-chain cautions users should handle before use.
Before installing, pin and verify the Instapaper CLI version where possible. Do not put a real password directly into copied shell commands; use an interactive prompt, a protected secret manager, or another method that avoids shell history and logs. Review destructive commands before running them, especially delete, folder delete, import, and bulk mutation operations.
SKILL.md:15Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
references/commands.md:10Password May Be Disclosed Through Shell History and Command Logging
Referenced artifact was not completely inspected
- `references/commands.md`: command-by-command examples for auth, list/export/import, mutations, folders, highlights, and text.
The example encourages supplying a password via a shell pipeline using a literal string. While --password-stdin is generally safer than passing a password directly as a command-line argument, this documented pattern still normalizes insecure credential handling in shell history, scripts, screenshots, and copied examples, and it provides no warning about secret hygiene. In an automation-focused CLI skill, users may reuse the pattern with real credentials in unsafe ways.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Login (stdin password):
- `printf '%s' "pass" | ip auth login --username "you@example.com" --password-stdin`
- Add `--no-input` to disable prompts.
- Check auth:
- `ip auth status` or `ip --json auth status`
- Config:
No suspicious patterns detected.