T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party SDK Is Given Wallet Signing Authority
- Content
View full analysis
- Remediation
View remediation
``` 2. Commit a lockfile and use `npm ci` in automated or reproducible environments. 3. Verify package integrity, publisher provenance, release signatures, and the resolved dependency tree before execution. 4. Reference a reviewed commit hash or signed release tag instead of the mutable `master` branch. 5. Audit the SDK paths responsible for: - Signer handling - Session-permission construction - Executor-address selection - Workflow serialization - Network requests - On-chain transaction submission 6. Do not prohibit security review of upstream source and documentation. Clearly distinguish unsupported examples from material that should still be inspected for security purposes. 7. Use a dedicated low-value wallet for workflow deployment rather than a primary wallet. 8. Add explicit transaction and permission previews before requesting signatures, including chain, target, function, value, token allowance, validity period, execution count, and executor address. 9. Where supported, use a constrained signing interface or hardware wallet requiring user confirmation instead of exposing an unattended software signer to the SDK. 10. Validate the SDK-provided executor address against a separately published, versioned allowlist before granting permissions. ]]>
