T08 · Insecure Dependencies
- Location
SKILL.md:88- Finding
Unpinned Third-Party CLI Execution and Unverified Global Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```markdown ### Step 4: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill instructs the agent to execute the `skills` npm package through `npx` without specifying an exact reviewed version. When an appropriate local package is unavailable, `npx` may download and execute the package currently published under that registry name. The project contains no lockfile, integrity hash, provenance requirement, or version constraint that would ensure the executed CLI is the same artifact that was previously reviewed. The CLI is subsequently used to install skills from “GitHub or other sources.” The documented workflow does not require source allowlisting, publisher verification, commit pinning, signature validation, dependency inspection, or review of the downloaded skill before activation. The installation command combines two risk-increasing options: - `-g` installs the selected skill globally at the user level, expanding its effect beyond the current project. - `-y` suppresses interactive confirmation, reducing the opportunity for the user to inspect ...[truncated 2176 chars]- Remediation
View remediation
find ``` Validate the precise package name and version before documenting this command. 2. Commit and verify package integrity information where the execution environment permits it. Require registry provenance, signatures, or cryptographic checksums for downloaded artifacts. 3. Restrict skill installation to an explicit allowlist of trusted publishers, repositories, and canonical HTTPS sources. 4. Pin installed skills to reviewed immutable commit hashes, release tags backed by verified signatures, or content digests rather than mutable branch names or search-result aliases. 5. Remove `-y` from the default workflow. Require explicit, informed user confirmation that displays: - The resolved publisher and repository. - The exact version or commit. - The installation destination. - Requested scripts and dependencies. - Whether the installation is global. 6. Avoid `-g` by default. Install skills into an isolated project-local directory or disposable sandbox with least privilege. 7. Download and inspect the complete skill package before activation. Review instruction files, scripts, lifecycle hooks, dependencies, symbolic links, and references to remote executable content. 8. Disable npm lifecycle scripts during acquisition when feasible, then enable only reviewed execution paths: ```bash npm install --ignore-scripts ``` 9. Run third-party discovery and installation tooling in a sandbox with restricted filesystem, credential, environment-variable, and network access. 10. Document an approval policy requiring users to authorize the exact resolved artifact rather than merely consenting to a broad package name or search result. ]]>
