T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unverifiable Precompiled Binary Retrieved from an External Release Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–126
Vulnerability Type: Supply-chain exposure through a remotely hosted precompiled dependency
Risk Level: HighEvidence
markdown This tool includes a compiled Rust binary. Source code is available at: - Gitee: https://gitee.com/random_player/cmic-skill-scanner - All releases include SHA-256 checksums for integrity verification - Build from source: `cargo build --release` (see repo README)markdown | macOS ARM64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-darwin-arm64-v0.4.0.zip | | Linux x64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-amd64-v0.4.0.zip | | Linux ARM64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-arm64-v0.4.0.zip | - darwin-arm64: `bd78d3861a545ad52e2f51b8d072efe1d7604850f4a7049d99a840387a341c6a` - linux-amd64: `1b4997f7b2a4e4dcf9b0d7edcc65755e13a03a258d795ee1abcc35dcab3d5a86` - linux-arm64: `071b0c404b840aeb4e4d493b3a2513390ed629e0f07e4b79a0b5bc908f1c2d1c`bash shasum -a 256 skillscan-wrapper ./skillscan-wrapper review /path/to/skill --format markdownTechnical Analysis
The audited package contains only
SKILL.md; it does not include the referenced binary or corresponding Rust source code. The documented workflow directs users to retrieve a precompiled executable from an external Gitee repository and run it locally. Consequently, the executable's filesystem access, network behavior, upload implementation, external-engine behavior, and claimed security restrictions cannot be verified from the audited artifact.Fixed SHA-256 values provide integrity checking only when users compare the computed value with a trustworthy expected value. The documented command merely prints the calculated digest and does not enforce comparison o ...[truncated 2006 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete Rust source, lockfile, build configuration, and dependency metadata in the audited package.
- Prefer building the executable from reviewed source in a reproducible build environment rather than directing users to run an opaque binary.
- Publish reproducible-build instructions and allow users to compare locally built artifacts with released binaries.
- Sign release archives and checksum manifests with a cryptographic signing key whose public key or fingerprint is distributed through an independent trusted channel.
- Replace the checksum-printing instruction with an enforced verification command that fails closed before execution, such as a platform-appropriate checksum manifest check.
- Host expected checksums or signature fingerprints independently from the release assets to reduce single-source compromise risk.
- Pin and audit all dependencies, including any external scanning engine, and document its source, version, permissions, and network behavior.
- Run the scanner with least privilege in a sandbox or container. Restrict filesystem access to the selected scan directory, disable network access by default, and explicitly enable only required destinations.
- Add automated release provenance, continuous dependency scanning, and verification tests that ensure distributed binaries correspond to the reviewed source.
