T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Remote Dependency Installed Globally from a Mutable Git Repository
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4; repeated at line 30
Vulnerability Type: Unpinned third-party dependency from an unsafe mutable source
Risk Level: MediumVulnerable code snippet:
yaml metadata: {"clawdbot":{"emoji":"🔍","os":["darwin","linux"],"requires":{"bins":["qmd"]},"install":[{"id":"bun-qmd","kind":"shell","command":"bun install -g https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd via Bun"}]}}The installation instruction is repeated later as:
bash bun install -g https://github.com/tobi/qmdTechnical Analysis
The Skill instructs the environment to install QMD globally and directly from a GitHub repository URL. The source is not pinned to an immutable commit hash or a cryptographically verified release artifact. Consequently, the code installed when this command is executed may differ from the code that existed when the Skill was reviewed.
Because this is a global Bun installation, package installation hooks and subsequently invoked QMD code execute with the privileges of the user running Bun. The audit found no evidence that the current Skill itself contains a malicious payload; the risk arises from the mutable external dependency and its transitive supply chain.
Attack Path
- An attacker compromises the upstream QMD repository, a maintainer account, or a dependency used by the package.
- The attacker modifies the repository's default revision or installation behavior to include malicious code.
- A user or agent follows the Skill's installation instruction:
bun install -g https://github.com/tobi/qmd. - Bun downloads the modified, attacker-controlled content because no immutable revision or integrity value is specified.
- Malicious lifecycle code may execute during installation, or attacker-controlled logic may execute when the installed
qmdcommand is later invoked. - The payload operates with the invoking user's ...[truncated 766 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the installation to a reviewed, immutable commit hash or a specific trusted release instead of the repository's mutable default revision.
- Prefer an official release artifact with a published cryptographic checksum or signature, and verify its integrity before installation.
- Record and audit the complete transitive dependency graph using an appropriate lockfile.
- Avoid global installation where possible. Install the tool in an isolated project, container, sandbox, or dedicated low-privilege environment.
- Disable package lifecycle scripts during installation when they are unnecessary and supported by the package manager.
- Review upstream source changes before updating the pinned revision, and use automated dependency and provenance scanning.
- Run QMD with access limited to the specific document collections required for the task, rather than granting broad filesystem access.
