T08 · Insecure Dependencies
- Location
SKILL.md:57- Finding
Skill files are downloaded from a mutable repository branch without integrity verification
- Content
View full analysis
.agent/skills/prove-before-act/SKILL.md # Reference Manuals for f in certification x402 mcp; do curl -sL "https://raw.githubusercontent.com/jasonxkensei/prove-before-act/main/clawhub-publish/xproof/references/${f}.md" \ > ".agent/skills/prove-before-act/references/${f}.md" done ``` ### Technical Analysis The installation instructions download the core skill and its reference documents from the mutable `main` branch. No immutable commit identifier, release tag, checksum, or signature is used to verify the downloaded content. Although the downloaded files are Markdown rather than native executables, they are agent instructions. Their effective behavior begins when an agent loads and follows them. A compromised upstream repository, maintainer account, build process, or delivery path could therefore replace the reviewed instructions with content that directs the agent to disclose data, invoke privileged tools, make payments, or retrieve and execute additional payloads. The use of HTTPS protects transport integrity but does not establish that the retrieved content is the same version that was audited. The comment identifying the repository as canonical does not provide cryptographic verification. This exceeds minimum privilege because installation only requires a known, reviewed version of the documentation; granting the current upstream branch continuing control over installed instructions is unnecessary. ### Attack Path 1. An attacker compromises an upstream maintainer account, GitHub token, repository workflow, or another mecha ...[truncated 1533 chars]- Remediation
View remediation
" BASE="https://raw.githubusercontent.com/jasonxkensei/prove-before-act/${COMMIT}/clawhub-publish/xproof" ``` - Publish SHA-256 digests through a separately authenticated release channel and verify each file before moving it into the active skill directory: ```bash curl --fail --show-error --location "$BASE/SKILL.md" -o SKILL.md.tmp printf '%s %s\n' "" "SKILL.md.tmp" | sha256sum --check - mv SKILL.md.tmp .agent/skills/prove-before-act/SKILL.md ``` - Prefer signed release artifacts and verify a trusted maintainer signature or Sigstore attestation. - Download into a staging directory and activate the files only after every integrity check succeeds. - Use `curl --fail --show-error` so HTTP failures do not silently create empty or error-page files. - Review updates before changing the pinned commit or digest; do not perform automatic runtime refreshes. - Restrict installed skill instructions from directly authorizing secret access, arbitrary tool execution, or payments without explicit user approval. ]]>
