T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unreviewed Third-Party Skill Installation Workflow
- Content
View full analysis
--limit 10 ``` ### 3. 自动安装 ```bash python3 scripts/install_skills.py --skills <技能列表> ``` ### 4. 进化记录 ```bash python3 scripts/log_evolution.py --cycle <周期号> --changes <变更描述> ``` ``` ### Technical Analysis The documented workflow instructs the agent to search a skill registry and automatically install selected third-party skills. It does not specify any of the following supply-chain controls: - An allowlist of trusted publishers or packages - Exact version pinning - Cryptographic signature or checksum verification - Source-code and instruction review before installation - Permission disclosure and least-privilege enforcement - Sandboxed execution - Explicit user approval for each installation A skill can contain executable scripts and agent-facing instructions. Installing an untrusted or compromised skill can therefore introduce malicious code, instruction hijacking, credential access, or other unauthorized behavior into the agent environment. The referenced `scripts/search_skills.py` and `scripts/install_skills.py` files are absent from the audited artifact. Consequently, the packaged Python code cannot currently perform this workflow directly. Exploitation requires either a future implementation of those scripts or an agent interpreting and carrying out the documented instructions through other available tools. ### Attack Path 1. An attacker publishes a malicious or typosquatted skill to the registry searched by the workflow. 2. The attacker selects metadata and keywords likely to match an agent capability-gap search. 3. The agent follows `SKILL.md` and searches for skills without restricting results to trusted publishers. 4. The malicious skill is selected and installed withou ...[truncated 971 chars]- Remediation
View remediation
