T08 · Insecure Dependencies
- Location
references/popular_skills.md:12- Finding
Unpinned Third-Party Skill Installation Creates Supply-Chain Risk
- Content
View full analysis
`). ``` `references/popular_skills.md:12-16`: ```markdown - **Capability Evolver** (`capability-evolver`) - **Downloads**: 35,000+ - **Description**: AI self-evolution engine that autonomously audits and rewrites agent behavior. - **Link**: [https://clawhub.ai/skills/capability-evolver](https://clawhub.ai/skills/capability-evolver) - **Install**: `clawhub install capability-evolver` ``` `references/recommendation_logic.md:17-20`: ```markdown ## Selection Criteria 1. **Popularity**: Prioritize skills with >10,000 downloads or high star counts. 2. **Official/Verified**: Prefer official integrations (e.g., `github`, `linear`) for stability. 3. **Contextual Fit**: If the user is currently working on a specific project (e.g., a React app), prioritize `fast-io` or `github`. 4. **Recent Trends**: Mention skills that are currently trending in the community (e.g., `capability-evolver`). ``` ### Technical Analysis The recommendation workflow provides installation c ...[truncated 2657 chars]- Remediation
View remediation
@ ``` 9. Maintain an auditable allowlist containing the reviewed version, publisher identity, source repository, expected digest, review date, and required permissions. 10. Revalidate catalog claims and pinned artifacts periodically, and disable recommendations when verification data is stale or unavailable. ]]>
