T08 · Insecure Dependencies
- Location
SKILL.md:101- Finding
Unpinned Third-Party CLI Installed Globally from Mutable Package Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 101-104; dependency reiterated at line 251
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: MediumVulnerable code:
bash npm install -g @maton/cli brew install maton-ai/cli/matonThe dependency table also directs users to install the same unpinned package:
markdown | Maton CLI | CLI tool | Required | `npm install -g @maton/cli` |Technical Analysis
The Skill instructs the Agent or user to install the latest available version of a third-party CLI globally without specifying an audited version, lockfile, package integrity hash, or trusted release signature. The project contains only
SKILL.md; therefore, the behavior of the required CLI cannot be reviewed as part of this audit.An npm installation can execute package lifecycle scripts during installation. A Homebrew installation from an external tap similarly delegates installation behavior to remotely maintained formulae and artifacts. Because no version is pinned, the effective executable and installation logic can change after this Skill has been reviewed.
This creates a supply-chain trust boundary in which compromise of the package publisher, package registry account, Homebrew tap, release artifact, or a future dependency version could introduce attacker-controlled code. Global installation also makes the resulting executable broadly available to subsequent shell and Agent operations.
Attack Path
- An attacker compromises the npm publisher, Homebrew tap, release infrastructure, or an upstream dependency used by the Maton CLI.
- The attacker publishes a malicious release under the same package or tap referenced by the Skill.
- An Agent or user follows the documented setup instructions without a pinned version or integrity verification.
- The package manager resolves the mutable latest release and downloads the compromised pa ...[truncated 1368 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the Maton CLI to a specifically reviewed version instead of installing the mutable latest release.
- Provide and verify official cryptographic checksums or signed release metadata before installation.
- For npm, use a project-local dependency with an exact version and committed lockfile rather than a global installation.
- Review package lifecycle scripts and consider disabling them during installation where functionality permits.
- For Homebrew, pin an audited formula revision and document the official tap ownership and artifact verification process.
- Execute the CLI in a least-privileged sandbox or container with access limited to the files, network destinations, and credentials required for the current Linear operation.
- Avoid installing or running the CLI with administrative privileges.
- Supply API credentials only at execution time, restrict OAuth scopes to required Linear operations, and rotate credentials if dependency compromise is suspected.
- Add dependency provenance, release-signature validation, and periodic vulnerability monitoring to the Skill's documented installation workflow.
