T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Skill Installation from a Mutable Remote Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31–38
Vulnerability Type: Unverified and unpinned third-party dependency installation
Risk Level: MediumEvidence
bash npx skills add https://github.com/zzxCoding/skills --skill flydb npx skills add https://github.com/zzxCoding/skills --skill flydb-cli-release npx skills add https://github.com/zzxCoding/skills --skill flydb-migration-scripts npx skills add https://github.com/zzxCoding/skills --skill flydb-multi-environmentTechnical Analysis
The documented installation procedure invokes an
npx-resolved installer and retrieves Skills directly from a mutable GitHub repository. The repository reference is not pinned to an immutable commit, signed release, or verified artifact checksum. Consequently, the content installed by these commands can differ from the content that was originally reviewed.This creates two supply-chain trust dependencies:
- The package and executable resolved by
npxmust remain trustworthy. - The latest content served by the remote repository must remain trustworthy.
If either source, its publisher account, or its release process is compromised, the commands can install modified Skill instructions or related executable components without a local integrity check. This audit found no evidence that the current upstream content is malicious; the vulnerability is the unsafe, mutable installation mechanism.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the package distribution path used by
npx. - The attacker modifies a child Skill or causes the installer to retrieve attacker-controlled content.
- A user or agent follows the installation commands in
SKILL.md. - The unverified content is written into the agent's Skills directory.
- When the installed Skill is subsequently loaded, its altered instructions or bundled components execute with the permissions ...[truncated 1123 chars]
- The package and executable resolved by
- Remediation
View remediation
Remediation Suggestions
- Pin the remote repository to a reviewed, immutable commit hash instead of installing from its moving default branch.
- Pin the
npxpackage to an exact reviewed version and avoid implicit installation of the latest release. - Publish checksums or signed manifests for every child Skill and verify them before installation.
- Prefer vendoring reviewed child Skills with the parent package when licensing and maintenance requirements permit it.
- Add a mandatory review step that displays and inspects all downloaded Skill files before placing them in an active Skills directory.
- Perform installation in a restricted environment without production credentials, database access, or unnecessary filesystem permissions.
- Maintain an allowlist of approved repository commits and installer versions.
- Document rollback procedures so an altered or compromised Skill can be removed from every agent environment.
- Apply the same pinning and verification controls to the alternative SkillHub installation channel described later in
SKILL.md; do not delegate installation to mutable remote instructions without integrity validation.
