T08 · Insecure Dependencies
- Location
README.md:75- Finding
Installation from a Mutable, Unverified GitHub Repository
- Content
View full analysis
Vulnerability Details
File Location:
README.md:75-77
Vulnerability Type: Supply-chain exposure through a mutable installation source
Risk Level: MediumVulnerable Code:
bash clawhub install https://github.com/lijingxu007/travel-Inbound-customizer.gitTechnical Analysis
The documented installation command retrieves the Skill directly from a mutable GitHub repository without pinning an immutable commit hash, verifying an artifact checksum, or requiring a cryptographic signature. Consequently, the content installed by this command can differ from the version reviewed during this audit.
This is an insecure supply-chain practice rather than evidence that the repository currently contains malicious content. If the repository, maintainer account, or relevant branch is compromised, an attacker could modify files such as
SKILL.mdortools.py. A later installation would then retrieve those unreviewed changes.Attack Path
- An attacker compromises the GitHub repository, maintainer account, credentials, or default-branch update process.
- The attacker adds malicious instructions to
SKILL.mdor executable behavior totools.py. - A user follows the documented installation command.
- ClawHub retrieves the current mutable repository content rather than the audited revision.
- The modified instructions or Python code execute when the installed Skill is loaded or invoked.
Impact Assessment
The precise impact depends on the permissions granted to the Skill runtime and the content introduced by the attacker. Potential impact includes modification of Agent behavior, unauthorized network requests, access to environment variables available to the process, and disclosure or alteration of customer travel data and Feishu records.
The command does not itself establish elevated privileges, persistence, or current compromise. The exposure is limited by the permissions and credentials availab ...[truncated 26 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable repository URL with an installation reference pinned to a reviewed immutable commit or release artifact.
- Publish signed releases and require signature verification before installation.
- Provide a cryptographic checksum for the complete Skill artifact and verify it during installation.
- Prefer a trusted package registry that supports immutable versions, provenance attestations, and integrity verification.
- Protect the source repository with multi-factor authentication, branch protection, mandatory review, and restricted release permissions.
- Document a controlled update process so new revisions receive security review before deployment.
