T08 · Insecure Dependencies
- Location
SKILL.md:61- Finding
Unverified Third-Party Skill Installation and Immediate Trust
- Content
View full analysis
``` After install, inform the user: - The skill is installed - They need to **start a new session** (or the agent needs a restart) for the skill to take effect - Alternatively, they can read the new SKILL.md immediately to use it in the current session ### 5. Immediate Use (optional) If the user wants to use the skill right away in the current session: 1. Read the newly installed skill's SKILL.md 2. Follow its instructions to handle the original request ``` ### Technical Analysis The workflow installs packages discovered through a public skill registry and permits the agent to immediately read and follow their instructions. Although user confirmation is required, the workflow does not require any security assessment before installation or use. In particular, it does not require: - Verification of the publisher or package provenance - Pinning or verification of an immutable package version - Package integrity or signature validation - Inspection of all installed files and scripts - Review of requested permissions and tool access - Detection of obfuscated instructions or remote payload retrieval - Comparison between the reviewed package and the installed artifact - Isolation or sandboxing before following the installed instructions User confirmation alone is not a sufficient supply-chain control because the user is only shown a name, description, and relevance assessment. Those registry metadata fields do not demonstrate that the package contents are safe. The immediate-use workflow creates a trust transition from unverified registry content to active agent instructions. A malicious or compr ...[truncated 1967 chars]- Remediation
View remediation
