T08 · Insecure Dependencies
Note
- Location
references/INSTALL.md:7- Finding
Execution of an Unpinned Remote Repository and Dependency Chain
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent and read-only at the MCP level, but its setup asks users to run unpinned code from an external repository.
Install only if you are comfortable running the external Switchyard repository locally. Prefer checking out a known commit or signed release, reviewing package scripts and dependencies, using a frozen lockfile or ignoring lifecycle scripts where possible, and running the setup in a least-privilege sandbox without sensitive credentials.
references/INSTALL.md:7Execution of an Unpinned Remote Repository and Dependency Chain
Detected: suspicious.install_untrusted_source