T08 · Insecure Dependencies
- Location
SKILL.md:82- Finding
Unverified Remote Font Archive Is Installed Without Integrity Validation
- Content
View full analysis
/dev/null && fc-cache -f "$FONT_DIR" echo "TikTok Sans: installed to $FONT_DIR" fi ``` ### Technical Analysis The mandatory preflight procedure downloads a mutable archive from a third-party font-distribution website and installs its contents without validating a cryptographic digest or signature. The archive is neither version-pinned nor restricted to a known artifact. A compromised distribution server, DNS or account takeover, or malicious upstream archive replacement could therefore change the bytes installed after the Skill has been audited. Font files are subsequently processed by `fc-cache`, FFmpeg, and operating-system font libraries. A crafted font could exploit a vulnerability in one of those parsers. The wildcard copy also accepts every matching `TikTokSans*.ttf` file rather than an explicit allowlist. The download is data retrieval rather than the `curl | bash` behavior identified by the pre-scan. No actual `curl | bash` command was found in the audited files. Nevertheless, automatically processing an unverified remote binary artifact remains a supply-chain risk. ### Attack Path 1. An ...[truncated 957 chars]- Remediation
View remediation
