T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Installation from a Mutable Remote Git Repository
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5 and 27
Vulnerability Type: Supply-chain risk from an unpinned remote dependency
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"🔍","os":["darwin","linux"],"requires":{"bins":["qmd"]},"install":[{"id":"bun-qmd","kind":"shell","command":"bun install -g https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd via Bun"}]}}bash bun install -g https://github.com/tobi/qmdTechnical Analysis
The installation command retrieves and globally installs executable software directly from a mutable Git repository without pinning an audited commit hash or immutable release artifact. Consequently, the code executed at installation time may differ from the version originally reviewed.
The repository URL is consistent with the Skill's declared homepage, and there is no evidence of typosquatting or current malicious behavior. Nevertheless, compromise of the upstream repository, its maintainers, or the relevant branch could cause altered package code or installation scripts to execute with the installing user's permissions. Global installation also places the resulting executable in the user's tool path, increasing the duration and scope of exposure.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the mutable branch resolved by the Git URL.
- The attacker modifies package code or lifecycle scripts while preserving expected
qmdfunctionality or appearance. - A user or agent follows the Skill's installation instruction.
- Bun downloads the current, attacker-controlled repository state and executes any applicable installation or lifecycle behavior.
- The installed
qmdexecutable subsequently runs with the invoking user's permissions and can access resources available to that account.
Impact Assessment
Successful exploitation could permit arbitra ...[truncated 721 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a specific audited commit hash or immutable, signed release rather than a mutable repository reference.
- Prefer a trusted package registry release that supplies integrity metadata, and verify the expected checksum or signature before installation.
- Record the approved version and digest in the Skill documentation so installations are reproducible.
- Review package lifecycle scripts and transitive dependencies before approving an update.
- Avoid elevated installation privileges and run
qmdunder a least-privileged user with access only to collections the user explicitly selects. - Require explicit user confirmation before global installation or creation of a scheduled reindex task.
- For scheduled execution, use absolute paths to the verified executable and document how to inspect and remove the task.
