T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned External Skill Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11–15
Vulnerability Type: Unpinned and unaudited third-party dependencies
Risk Level: MediumVulnerable Code
markdown Install the **Council Champion** + operator for complete system integration: ```bash npx clawhub@latest install deepseekoracle/lygo-champion-lightfather npx clawhub@latest install deepseekoracle/lygo-protocol-stack-operatortext ### Technical Analysis The documented installation procedure invokes the mutable `latest` release of `clawhub` through `npx` and installs two externally maintained Skills. Neither the installer nor the companion Skills are pinned to an immutable version or cryptographic digest. Consequently, the components retrieved when a user follows these instructions may differ from those available when this project was audited. The external components are absent from the audited artifact, so their instructions, scripts, permissions, and runtime behavior cannot be verified here. This creates a supply-chain trust boundary in which compromise of the package source, publisher account, installer, or a future release could cause externally controlled code or Skill instructions to be installed with the invoking user's privileges. ### Attack Path 1. An attacker compromises the publisher account, package source, installer distribution, or a future mutable release of one of the referenced components. 2. The attacker adds malicious code or agent instructions to the compromised release. 3. A user follows the installation commands in `SKILL.md`. 4. `npx` retrieves the current `clawhub@latest` package, which then retrieves the external Skills. 5. The unaudited payload is installed and may execute code or influence subsequent agent behavior within the permissions available to the installer or Skill runtime. ### Impact Assessment Successful exploitation could provide the malicious dependency with the privileges granted to the invoking process or Skill runtime ...[truncated 543 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
clawhub@latestwith a specifically reviewed and pinned installer version. - Pin both companion Skills to immutable versions, commit identifiers, or cryptographic digests.
- Verify downloaded artifacts against published checksums or signatures before installation.
- Document each dependency's required permissions, network behavior, scripts, and side effects.
- Vendor required companion content into the reviewed package where licensing and maintenance constraints permit.
- Re-audit dependencies whenever their pinned versions change.
- Clearly distinguish optional external integrations from functionality included in and covered by this project's audit.
- Replace
