T08 · Insecure Dependencies
- Location
README.md:38- Finding
Unpinned and Unverified Skill Installation and Update Sources
- Content
View full analysis
Vulnerability Details
File Location:
README.md:38-52;SKILL.md:196-200
Vulnerability Type: Supply-chain exposure through mutable and unverified external sources
Risk Level: MediumVulnerable Code
README.md:38-52:bash mkdir -p ~/.claude/skills/pages curl -o ~/.claude/skills/pages/SKILL.md https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.mdbash npx skills add haah-ing/pages-skillbash hermes skills install pagesSKILL.md:196-200:markdown ## Updating To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:https://raw.githubusercontent.com/haah-ing/pages-skill/main/SKILL.md
text Technical Analysis
The documented installation and update processes obtain content from sources whose exact revisions are not pinned or cryptographically verified. The direct download uses the mutable GitHub
mainbranch rather than an immutable commit or signed release. Thenpxand Hermes commands similarly omit explicit, reviewed versions and integrity-verification requirements.Although the
curlcommand does not pipe downloaded data directly to a shell, it writes the remote file into the Agent's active skill directory. The resultingSKILL.mdis subsequently treated as trusted Agent instructions. Consequently, a future upstream change or compromise can alter the effective behavior after the version reviewed in this audit.This is a supply-chain weakness rather than evidence that the current upstream content is malicious. No malicious embedded script or direct remote shell-execution command was identified in the audited files.
Attack Path
- An attacker compromises an upstream repository, package, publication account, distribution service, or maintainer credential.
- The attacker modifies the mutable
mainbranch or publishes a compromised package version. - A user follows th ...[truncated 1215 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin direct downloads to an immutable, reviewed Git commit or versioned release instead of
main. - Publish SHA-256 checksums or cryptographic signatures for every release and require users to verify them before installation.
- Download updates to a temporary review location rather than replacing the active
SKILL.mdimmediately. - Compare the downloaded file with the currently installed version and require explicit user approval before activation.
- Pin exact package versions in
npxand Hermes installation examples where supported. - Document the expected package publisher, repository identity, release version, and integrity value to reduce dependency-confusion and account-impersonation risks.
- Prefer signed release artifacts with a documented key-verification procedure.
- Avoid automatic updates from mutable branches and preserve a known-good version for rollback.
- Pin direct downloads to an immutable, reviewed Git commit or versioned release instead of
