T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Executable Package Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-style skill for using the coala-client CLI; its higher-risk features are disclosed and user-initiated, though users should treat remote imports, shell execution, and plaintext API-key files carefully.
Install only if you trust the coala-client package source. Review remote CWL, ZIP, and skill sources before importing them, be cautious with sandboxed shell commands, and protect any API keys stored in ~/.config/coala/env with restrictive file permissions or a secret manager.
SKILL.md:5Unpinned Executable Package Dependency
SKILL.md:18Plaintext API Credential Storage Guidance Without Permission Hardening
Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.
## Chat commands
- `/help`, `/exit`, `/quit`, `/clear`
- `/tools` — list MCP tools
- `/servers` — list connected MCP servers
- `/skill` — list skills; `/skill <name>` — load a skill
- `/model` — show model info
The description advertises an optional sandbox for running shell commands but does not warn that command execution is inherently risky even when sandboxed. Users may infer this is routine and safe, when in practice shell execution can still affect local files, consume resources, or expose data depending on sandbox configuration.
The skill instructs users to import CWL toolsets and skills from local or remote ZIP/HTTP(S) sources without any warning that doing so changes local configuration and can introduce executable MCP integrations. In this context, imported toolsets create server definitions and per-toolset runtime files, so a user may trust unvetted remote content and unintentionally add code-capable integrations to future sessions.