T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned External Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23-27
Vulnerability Type: Unverified and mutable external dependency
Risk Level: MediumVulnerable Code
text Use the current OpenClawCash skill instead: https://clawhub.ai/macd2/open-claw-cash Do not continue setup with this legacy copy. Install the replacement skill from the URL above and follow its current instructions.Technical Analysis
The Skill instructs users or agents to install and follow a replacement Skill hosted at an external URL. The reference does not specify an immutable version, cryptographic digest, verified signature, or locally auditable copy.
Consequently, the effective replacement content may change after this artifact has been reviewed. If the external account, hosting service, publication workflow, or referenced Skill is compromised, the replacement could supply instructions or executable components that were not covered by this audit.
The reviewed file does not itself retrieve or execute remote code, and there is no evidence that the referenced replacement is malicious. The issue is an insecure supply-chain trust boundary caused by directing installation from a mutable, unpinned source.
Attack Path
- An attacker compromises the publisher account, external hosting platform, or replacement Skill's release process.
- The attacker modifies the replacement Skill or its instructions while retaining the same URL.
- A user or agent follows the directive in
SKILL.mdand installs the externally hosted replacement. - The replacement is loaded with the tools and permissions available to the agent.
- Malicious replacement content may then misuse those capabilities without having been assessed as part of this audit.
Impact Assessment
The vulnerable artifact grants no privileges directly and contains no executable scripts. Potential impact depends on the replacement Skill and the permissions availabl ...[truncated 415 chars]
- Remediation
View remediation
Remediation Suggestions
- Reference an immutable, explicitly approved release of the replacement Skill rather than a mutable landing-page URL.
- Record and verify a cryptographic digest for the exact replacement package before installation.
- Require publisher or package-signature verification through a trusted signing mechanism.
- Vendor a reviewed copy into a controlled repository when feasible, preserving its provenance and license information.
- Require a fresh security review whenever the replacement version or digest changes.
- Prevent agents from automatically installing or following externally hosted Skill instructions without explicit user approval.
- Install the replacement under least privilege, restricting credential access, filesystem access, network destinations, and executable tools to those strictly required.
