T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Package Execution and Unverified Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:30-33, 49, 87-93
Vulnerability Type: Supply-chain exposure through mutable third-party packages
Risk Level: MediumVulnerable Code
bash npx skills find [query] npx skills add <package> npx skills check npx skills updatebash npx skills find [query]bash npx skills add <owner/repo@skill> -g -yThe skill instructs the agent to execute
npx skillswithout pinning the CLI package to a reviewed version. It also directs the agent to install skills identified through external search results, globally and without an interactive confirmation prompt.Technical Analysis
An unqualified
npx skillsinvocation may download and execute the package version currently resolved by the npm registry. NeitherSKILL.mdnorpackage.jsonpins a reviewed CLI version, records an integrity hash, or declares the CLI as a locked dependency.The installation workflow additionally accepts an external
<owner/repo@skill>identifier and uses-g -y. Global installation increases the affected scope, while-ysuppresses the final confirmation opportunity. The documented process does not require repository allowlisting, commit pinning, source inspection, signature verification, or integrity validation before installation.Consequently, the behavior reviewed during this audit may differ from the code ultimately downloaded and executed.
Attack Path
- An attacker publishes a malicious or confusingly named npm package, compromises the package resolved as
skills, or compromises a subsequently resolved release. - Alternatively, an attacker controls or compromises a skill repository surfaced by the external search service.
- A user requests skill discovery, causing the agent to follow the documented
npx skills findworkflow. npxretrieves and executes the mutable, unpinned CLI package under the agent or user account.- The attacker-controlled result is selected for installatio ...[truncated 958 chars]
- An attacker publishes a malicious or confusingly named npm package, compromises the package resolved as
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an explicitly reviewed version, for example
npx skills@<reviewed-version>, rather than resolving the latest available release. - Prefer declaring the CLI in a lockfile-backed dependency set and executing the locally installed binary with immutable dependency resolution.
- Verify package provenance, signatures, and integrity metadata before execution.
- Pin installed skills to reviewed immutable commit hashes or signed releases rather than mutable repository references.
- Maintain an allowlist of trusted publishers and repositories.
- Download candidate skills into an isolated temporary directory and inspect their instructions, scripts, manifests, dependencies, and lifecycle hooks before installation.
- Run discovery and installation in a sandbox with minimal filesystem, credential, and network access.
- Remove
-gas the default and install into a project-scoped or otherwise isolated location. - Remove
-yand require explicit, informed user approval after displaying the exact source, version or commit, requested scope, and review results. - Document a rollback procedure for removing an installed skill and verifying that no unauthorized files or configuration remain.
- Pin the CLI to an explicitly reviewed version, for example
