T08 · Insecure Dependencies
- Location
SKILL.md:205- Finding
Unpinned Third-Party Skill Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 205–221
Vulnerability Type: Unpinned third-party dependencies from external sources
Risk Level: MediumThe vulnerable instructions are:
markdown Once formats are proven and accounts established, use [Post Bridge](https://www.post-bridge.com) to upload once and post everywhere, schedule a week in one sitting, and manage multiple accounts without logging in and out. For the posting mechanics, install the companion skill:npx skills add post-bridge-hq/agent-mode --skill post-bridge
text That skill wraps the Post Bridge API and `postbridge-cli` for media upload, scheduling, per-platform config and result tracking. Once you are past roughly 15 accounts the problem changes from growth to operations: keeping accounts un-restricted, reading per-account results, and knowing when a failure is worth fixing versus waiting out. That is a different skill:openclaw skills install @jackfriks/multi-account-operator
text Technical Analysis
The Skill recommends installing two externally maintained components without specifying immutable versions, commit hashes, checksums, or integrity metadata. The commands therefore resolve mutable third-party content at installation time. The downloaded components are not included in this repository and could not be reviewed as part of this audit.
This violates dependency integrity and reproducibility principles. Even if the current upstream packages are benign, a compromised maintainer account, transferred namespace, malicious update, or upstream repository compromise could cause the same documented commands to install different and potentially hostile content later.
Because the companion components are intended to perform media uploads, scheduling, platform configuration, and multi-account management, they may receive API credentials or authenticated access to social-media accounts. Their effective per ...[truncated 1697 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each external dependency to an immutable, reviewed version or commit hash rather than a mutable package identifier.
- Publish and verify cryptographic checksums, signatures, or package-manager integrity metadata before installation.
- Confirm publisher identity and ownership of each namespace and document the authoritative source repository.
- Review the exact pinned source and its transitive dependencies before recommending installation.
- Document the permissions, credentials, filesystem paths, and network destinations required by each companion component.
- Apply least privilege by using scoped API tokens and restricting filesystem and network access.
- Require explicit user approval after presenting the dependency source, pinned version, integrity value, and requested capabilities.
- Establish a controlled update process in which newer revisions are reviewed and repinned rather than automatically resolved.
- Prefer sandboxed execution and revoke or rotate credentials if dependency integrity cannot be established.
