T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Third-Party Installation Sources Can Execute Unaudited Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:28-34andREADME.md:34-42
Vulnerability Type: Supply-chain risk through mutable, unpinned installation sources
Risk Level: MediumVulnerable Code
SKILL.md:28-34:bash # Install this agent skill with skills.sh npx skills add adinvadim/2captcha-cli # Or install with ClawHub/OpenClaw openclaw skills install 2captcha # Install the CLI after reviewing the source git clone https://github.com/adinvadim/2captcha-cli.gitREADME.md:34-42:bash # skills.sh: Codex, Claude Code, Cursor, and other supported agents npx skills add adinvadim/2captcha-cli npx skills add adinvadim/2captcha-cli --global npx skills add adinvadim/2captcha-cli --agent codex npx skills use adinvadim/2captcha-cli@2captcha # OpenClaw / ClawHub openclaw skills install 2captcha clawhub install 2captchaTechnical Analysis
The documented installation procedures retrieve components from npm-backed tooling, skill registries, and the default branch of a Git repository without pinning immutable package versions, release artifacts, or Git commit hashes. No checksum or signature verification is prescribed.
Consequently, the code installed by a user at a later date may differ from the artifact reviewed in this audit. If an upstream account, package, registry entry, repository, or distribution channel is compromised, an attacker could replace the effective installation payload while retaining the expected project name.
This finding concerns the installation guidance rather than malicious behavior in the audited
solve-captchaexecutable. The executable's Base64 image encoding and communication withhttps://api.2captcha.comare consistent with its declared CAPTCHA-solving function and are explicitly disclosed in the documentation.Attack Path
- An attacker compromises an upstream maintainer account, repository, package, or skill-registry entry.
...[truncated 1194 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin npm-based installer packages to exact reviewed versions rather than relying on the latest package resolution.
- Pin skill installations to immutable, versioned releases where the relevant installer supports this.
- Replace unpinned repository cloning with checkout of an audited full Git commit hash:
bash git clone https://github.com/adinvadim/2captcha-cli.git cd 2captcha-cli git checkout --detach <audited-full-commit-hash> - Publish SHA-256 checksums for release artifacts and require verification before execution or linking.
- Sign releases and document signature verification using a trusted signing identity.
- Prefer installing the reviewed bundled executable instead of downloading a second mutable copy from an external source.
- Avoid global or privileged installation until integrity verification has completed.
- Add provenance information to the documentation, including the exact source revision corresponding to version
2.0.1. - Configure CI to reproduce release artifacts from the pinned source and validate their hashes before publication.
