T08 · Insecure Dependencies
- Location
SKILL.md:63- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
`. ``` ### Technical Analysis The skill instructs the agent to install plugins using only a short package name. It does not specify an exact version, immutable package digest, verified publisher, trusted registry, or signature-validation procedure. Consequently, the code installed during execution may differ from the dependency reviewed when this skill was audited. If the plugin registry, publisher account, package resolution mechanism, or one of the named packages is compromised, an attacker-controlled plugin could execute under the privileges of the `opencli` process. This is particularly sensitive because the skill declares and uses Alibaba API credentials, including `ALI_APP_KEY`, `ALI_APP_SECRET`, and `ALI_ACCESS_TOKEN`. A malicious plugin running in the same environment may be able to read these variables and access other files or credentials available to the process. ### Attack Path 1. An attacker compromises a plugin publisher or the package registry used by `opencli`, or publishes a package that is incorrectly resolved under one of the required names. 2. The agent runs `opencli plugin list` and determines that a required plugin is missing. 3. Following the skill instructions, the agent runs `opencli plugin install ` without pinning a version or validating the package origin and integrity. 4. The attacker-controlled plugin is installed and loaded by `opencli`. 5. The plugin executes with the local privileges of the agent process. 6. The malicious plugin reads available environment variables, including Alibaba credentials, or ac ...[truncated 820 chars]- Remediation
View remediation
