T08 · Insecure Dependencies
- Location
scripts/security.py:279- Finding
Unpinned Third-Party Skills Are Installed and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/security.py:179-207, 279-284, 573-578
Vulnerability Type: Supply-chain trust failure involving mutable, unverified third-party skills
Risk Level: HighVulnerable Code
python def installed_skills(workspace): """Return dict of installed security skill names -> their directories.""" sd = skills_dir(workspace) found = {} if not sd.exists(): return found for name in SKILLS: skill_dir = sd / name if skill_dir.is_dir() and (skill_dir / "SKILL.md").exists(): found[name] = skill_dir return found def run_skill(python, skill_dir, script_rel, args, workspace, ws_before=False, capture=True): """Run a skill's script with the given arguments. ws_before: if True, --workspace goes before the command args (subparser tools). if False, --workspace goes after the command args. """ script = skill_dir / script_rel if not script.exists(): return None, f"Script not found: {script}", 1 ws_args = ["--workspace", str(workspace)] if ws_before: cmd = [python, str(script)] + ws_args + args else: cmd = [python, str(script)] + args + ws_args try: result = subprocess.run( cmd, capture_output=capture, text=True, timeout=60, cwd=str(workspace), )python result = subprocess.run( [clawhub, "install", name, "--workdir", str(workspace)], capture_output=True, text=True, timeout=60, )python result = subprocess.run( [clawhub, "update", name, "--workdir", str(workspace)], capture_output=True, text=True, timeout=60, )Technical Analysis
The installation and update operations identify dependencies only by mutable ClawHub package names. The orchestrator does not pin audited versions or immutable digests and does not verify package checksums, cryptographi ...[truncated 2339 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each third-party skill to a reviewed immutable version and, where supported, a content digest or commit hash.
- Maintain a trusted manifest containing each skill's approved publisher identity, version, script paths, and cryptographic hashes.
- Verify package signatures and hashes before activation and before every execution, failing closed on missing or invalid verification data.
- Download updates into a staging directory, validate their complete contents, and activate them atomically only after verification succeeds.
- Do not treat the presence of
SKILL.mdas evidence of trust. Validate all executable files against the trusted manifest. - Reject symlinked skill directories and scripts, and check that resolved paths remain under the intended workspace skill directory.
- Check file ownership and permissions to prevent untrusted local users from replacing installed scripts.
- Restrict child processes using available operating-system sandboxing controls. Provide only required filesystem paths, environment variables, and network access.
- Remove unnecessary sensitive environment variables before invoking child skills.
- Record the verified package identity, version, digest, and verification result in an audit log for every installation, update, and execution.
