T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party Installation Without Artifact Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–29
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: MediumVulnerable Code Snippet
markdown ## 安装 / Install ```bash go install github.com/dongsheng123132/fastcp@latest或从 GitHub Releases 下载二进制。/ Or grab a binary from GitHub Releases.
text ### Technical Analysis The installation command uses the mutable `@latest` selector rather than an immutable, reviewed version or commit. Consequently, the code installed in the future may differ from the code that was assessed when the skill documentation was published. The alternative instruction to download a binary from GitHub Releases also does not specify a fixed release, expected cryptographic checksum, or signature-verification procedure. The executable implementation and its dependency manifest are not included in the audited project, so their behavior and transitive dependencies cannot be verified from this artifact. This creates a supply-chain trust boundary in which upstream repository control, release infrastructure, and dependencies determine the code ultimately executed by the user. ### Attack Path 1. An attacker compromises the upstream repository, maintainer account, release infrastructure, or a dependency used by the external project. 2. The attacker publishes a malicious version selected by `@latest`, or substitutes a malicious release binary. 3. A user or AI agent follows the documented installation instruction. 4. The package manager or user retrieves and executes the unreviewed component. 5. The malicious executable operates with the invoking user's permissions and can abuse its expected access to source and destination paths. ### Impact Assessment Successful exploitation grants malicious upstream code the same privileges as the account running the installation or invoking `fastcp`. The practical scope may include reading, modifying, deleting, or disclosing files acce ...[truncated 475 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a reviewed, fixed semantic version or immutable commit identifier. - Document the exact approved release version and upgrade it only after security review.
- Publish SHA-256 or stronger checksums for every supported release artifact.
- Provide cryptographic signature or provenance verification instructions, such as Sigstore verification or signed release manifests.
- Pin and audit transitive dependencies in the upstream project, and use automated dependency and provenance scanning.
- Recommend executing the utility with the minimum filesystem permissions required for the selected source and destination directories.
- Where feasible, vendor or include the reviewed source and build instructions so the effective implementation can be audited alongside the skill.
- Replace
