T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party Installation Commands Enable Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9-26
Vulnerability Type: Unpinned third-party packages and mutable repository sources
Risk Level: MediumVulnerable Code
bash **Companion Skills**: This is part of the Camino AI location intelligence suite. Install all available skills (camino-query, camino-places, camino-relationship, camino-context, camino-route, camino-journey, camino-real-estate, camino-hotel-finder, camino-ev-charger, camino-school-finder, camino-parking-finder, camino-fitness-finder, camino-safety-checker, camino-travel-planner) for comprehensive coverage. ```bash # Install all skills from repo npx skills add https://github.com/barneyjm/camino-skills # Or install specific skills npx skills add https://github.com/barneyjm/camino-skills --skill camino-contextVia clawhub:
bash npx clawhub@latest install camino-context # or: pnpm dlx clawhub@latest install camino-context # or: bunx clawhub@latest install camino-contexttext ### Technical Analysis The documented installation commands execute third-party package tooling and obtain skill content from mutable sources. The `clawhub@latest` specifier explicitly selects whichever release is current when the command is run. The GitHub repository URL is not pinned to a reviewed commit hash or signed release, and the `skills` runner is also invoked without an immutable package version. Consequently, the code executed or installed by these commands can differ from the artifact reviewed during this audit. Package runners such as `npx`, `pnpm dlx`, and `bunx` download and execute package code locally. If a package release, maintainer account, transitive dependency, package registry, or repository branch is compromised, a malicious replacement can execute during installation. This finding concerns the documented installation process. The audited `scripts/context.sh` itself does not retrieve or execute remote code ...[truncated 1380 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a specific, reviewed package version. - Pin the GitHub source to an immutable commit hash rather than a mutable default branch or tag.
- Pin the
skillspackage runner itself to a reviewed version. - Publish and verify cryptographic integrity hashes or signatures for installer packages and skill artifacts.
- Use package-manager lockfiles where applicable and review transitive dependency changes before upgrades.
- Run installation in a restricted environment without administrative privileges or unnecessary secrets.
- Document a controlled upgrade procedure so new versions are reviewed before installation instructions are updated.
- Replace
