T08 · Insecure Dependencies
- Location
SKILL.md:36- Finding
Unpinned and Unverified Third-Party Dependencies and Privileged Release Packages
- Content
View full analysis
:2025` - username: `admin` - password: `admin123` Agent standard install procedure: 1. Confirm the minimum missing inputs only: - target OS: Windows, Debian/Ubuntu, or RPM-based Linux - target architecture when relevant: `amd64` or `arm64`/`aarch64` - whether the agent can install directly on the target machine or must only provide user instructions - target machine IP if the user wants Web UI verification 2. Choose the install source: - prefer a matching package from Releases - prefer the Debian package when the agent can reach a Debian/Ubuntu host over SSH - only build from this repo when a needed Debian package is unavailable from Releases 3. Install by platform: - Windows: - download `installer_windows_amd64_v.exe` from Releases - if the agent cannot control the Windows desktop session, tell the user to run the installer manually - after installation, verify the service is running and open `http://:2025` - Debian/Ubuntu: ```bash sudo dpkg -i wolp-client__amd64.deb sudo systemctl status wolp.service ``` - RPM Linux: ```bash sudo rpm -ivh wolp-client--1.x86_64.rpm sudo systemctl status w ...[truncated 3373 chars]- Remediation
View remediation
wolp-client__amd64.deb" | sha256sum --check - ``` 5. Prefer cryptographic publisher signatures in addition to checksums: - Verify Authenticode signatures for Windows installers. - Verify repository or package signatures for Debian and RPM packages. - Document the expected publisher identity and signing-key fingerprint. 6. Pin GitHub downloads to a specific release version and immutable asset digest. Do not use floating “latest” URLs. 7. Separate download and verification from privileged installation. Do not invoke `sudo`, administrator elevation, or service installation unless artifact verification has succeeded. 8. Execute third-party components with the least privileges required. Harden the installed service with platform controls such as a dedicated service account, restricted filesystem access, and systemd sandboxing where supported. 9. Record the reviewed dependency versions, release URLs, checksums, signatures, and verification date in the Skill documentation so future changes can be detected. ]]>
