T08 · Insecure Dependencies
- Location
auto-discover.js:489- Finding
Default CLI workflow globally installs unreviewed remote skills
- Content
View full analysis
!a.startsWith('--')).join(' '); if (!query) { console.error('错误: 请提供查询内容'); process.exit(1); } (async () => { try { const result = await discoverAndInstall(query, { dryRun }); ``` ```javascript // auto-discover.js:489-491 const installResult = isClawhub ? await clawhubAdd(best.skill.fullName) : await skillsAdd(best.skill.fullName, { global: true, yes: true }); ``` ### Technical Analysis The CLI derives `dryRun` solely from the presence of `--dry-run`. Therefore, an ordinary invocation without this option passes `{ dryRun: false }` to the discovery workflow. When a result is selected, the installation path uses `global: true` and `yes: true`. This installs the selected third-party skill globally and suppresses interactive confirmation. The selected package originates from skills.sh or ClawHub and is not subjected to a local source-code audit before installation. This behavior contradicts the documented safe default of recommendation-only operation. The library API defaults to dry-run, but the command-line entry point overrides that default with `false`. ### Attack Path 1. An attacker publishes or compromises a skill whose metadata matches a commonly searched query. 2. A user invokes `skill-discovery "query"` without the optional `--dry-run` flag. 3. The project searches external registries and selects the highest-scoring result. 4. The CLI passes `dryRun: false` to the installation workflow. 5. The selected skill is installed globally with non-interactive confirmation enabled. 6. Code or instructions contained in the installed skill become available ...[truncated 477 chars]- Remediation
View remediation
