T08 · Insecure Dependencies
- Location
README.md:59- Finding
Unverified installation from a personal source repository
- Content
View full analysis
Vulnerability Details
File Location:
README.md:59-80; duplicated installation guidance appears inREADME.zh-CN.md:59-80, with the release URL also documented inevals/skill-eval-implementation-plan.md:211-215
Vulnerability Type: Unverified third-party source and release installation
Risk Level: MediumVulnerable Code
markdown ## Install ### Download Current release: **v0.16.2** - Release page: <https://github.com/kaisersong/kai-business-blueprint/releases/tag/v0.16.2> - Direct zip: <https://github.com/kaisersong/kai-business-blueprint/releases/download/v0.16.2/kai-business-blueprint-v0.16.2.zip> ### Claude Code ```bash git clone https://github.com/kaisersong/kai-business-blueprint ~/.claude/skills/kai-business-blueprintThen:
cd kai-business-blueprint && pip install -e .OpenClaw
bash git clone https://github.com/kaisersong/kai-business-blueprint ~/.openclaw/skills/kai-business-blueprint cd kai-business-blueprint && pip install -e .text The evaluation plan separately distributes the same unverified archive: ```markdown - <https://github.com/kaisersong/kai-business-blueprint/releases/tag/v0.16.2> - <https://github.com/kaisersong/kai-business-blueprint/releases/download/v0.16.2/kai-business-blueprint-v0.16.2.zip>Technical Analysis
The installation instructions direct users to clone a repository or download a release archive from an individual GitHub namespace and then install the resulting source in editable mode. No cryptographic checksum, signed release attestation, verified commit identifier, or reproducible-build verification is provided.
A versioned HTTPS GitHub URL protects transport integrity but does not protect against compromise of the publisher account, repository, release artifacts, or tag. A tag can also be moved unless independently pinned and verified. Editable installation additionall ...[truncated 2168 chars]
- Remediation
View remediation
Remediation Suggestions
- Publish a SHA-256 or stronger digest for every release archive through an independently protected channel.
- Sign release artifacts and tags using Sigstore, GitHub artifact attestations, or a protected signing key, and document mandatory verification commands.
- Pin clone-based installation to a full reviewed commit SHA rather than relying only on a mutable branch or tag.
- Protect release tags against deletion or movement and require reviewed, reproducible release workflows.
- Prefer an immutable, verified package distribution with locked dependency hashes if package installation is genuinely required.
- Remove
pip install -e .from end-user instructions if the bundled scripts can run without installation. Editable installs unnecessarily preserve trust in mutable working-tree content. - Provide verification instructions such as:
bash sha256sum kai-business-blueprint-v0.16.2.zip # Compare against the independently published expected digest before extraction. git clone https://github.com/kaisersong/kai-business-blueprint cd kai-business-blueprint git checkout --detach <reviewed-full-commit-sha> git verify-tag v0.16.2- Apply the same hardened installation guidance consistently in
README.md,README.zh-CN.md, andevals/skill-eval-implementation-plan.md. - Advise users to install and run the Skill in a least-privileged virtual environment or sandbox without unnecessary credentials or filesystem access.
