T08 · Insecure Dependencies
- Location
skill.md:32- Finding
Unpinned Installation of Mutable Remote Skill Content
- Content
View full analysis
~/.creditclaw/skills/creditcard/SKILL.md curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md curl -s https://creditclaw.com/creditcard/self-hosted-card.md > ~/.creditclaw/skills/creditcard/SELF-HOSTED-CARD.md curl -s https://creditclaw.com/creditcard/stripe-x402-wallet.md > ~/.creditclaw/skills/creditcard/STRIPE-X402-WALLET.md curl -s https://creditclaw.com/creditcard/heartbeat.md > ~/.creditclaw/skills/creditcard/HEARTBEAT.md curl -s https://creditclaw.com/creditcard/skill.json > ~/.creditclaw/skills/creditcard/package.json ``` The surrounding instructions also permit the Agent to read these documents directly from their live URLs. ### Technical Analysis The installation procedure downloads mutable Skill documents from live URLs and writes them into a persistent local Skill directory. It does not pin an immutable release, verify a cryptographic digest, validate a signed manifest, or otherwise confirm that the downloaded files are identical to the content reviewed during this audit. Skill Markdown files act as trusted Agent instructions. Consequently, changing the hosted content can change the effective behavior of the installed Skill without changing the audited package. An attacker who compromises the publishing server, deployment account, content pipeline, or relevant TLS trust path could replace the documents with instructions that manipulate payment operations, solicit secrets, or direct the Agent to run unsafe commands. The cu ...[truncated 2237 chars]- Remediation
View remediation
