T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned External Dependency and Unspecified Setup Script Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:4,10,63
Vulnerability Type: Unpinned third-party dependency and ambiguous external script execution
Risk Level: MediumComplete Code Snippet
yaml requires: "Fei2-Labs/skill-genie"markdown > **Requires [Skill Genie](https://github.com/Fei2-Labs/skill-genie)**. This skill generates rule files for the skill-genie `rules/` directory. Install skill-genie first, then run this skill.markdown Then run `setup.sh` to apply them.Technical Analysis
The skill identifies its dependency only by a mutable GitHub repository name. It does not pin a reviewed release or immutable commit, verify the integrity of downloaded artifacts, or establish a trusted installation path.
It subsequently instructs the agent to execute
setup.shwithout specifying an absolute or repository-relative path. The audited project does not contain that script, so neither its contents nor its security properties can be verified from the supplied package. The effective executable may vary according to the installed dependency revision and command-resolution context.Although installing a prerequisite and running its setup script can be legitimate, this design crosses a supply-chain execution boundary without sufficient provenance, integrity, or path controls.
Attack Path
- The user or agent installs or updates the mutable
Fei2-Labs/skill-geniedependency. - An attacker compromises the upstream repository or distribution path, or causes a malicious
setup.shto be selected from the effective working directory. - The user invokes this skill.
- The skill follows its documented process and runs the unresolved
setup.sh. - The malicious script executes with the permissions of the agent or user running the skill.
This path depends on compromise or substitution of an external component; no malicious script is embedded in the audited project itself.
Impact Assessment
Successful exploitatio ...[truncated 573 chars]
- The user or agent installs or updates the mutable
- Remediation
View remediation
Remediation Suggestions
- Pin Skill Genie to a reviewed release or immutable commit hash rather than a mutable repository reference.
- Verify downloaded artifacts using a trusted checksum or signature.
- Document the expected installation directory and invoke the script through an explicit trusted path, such as
./skill-genie/setup.sh. - Confirm that the resolved script is a regular file inside the expected dependency directory and reject symlinks or paths outside that directory where appropriate.
- Review and disclose the script's behavior and required permissions before execution.
- Display the exact command and resolved path, then require explicit user approval before running it.
- Execute the setup process with least privilege and in a restricted environment when practical.
- Prefer implementing the narrowly required rule-application behavior directly through reviewed operations rather than automatically executing an unspecified external script.
