T08 · Insecure Dependencies
- Location
SKILL.md:61- Finding
Unverified Third-Party Skill Installation and Immediate Trust
- Content
View full analysis
``` After install, inform the user: - The skill is installed - They need to **start a new session** (or the agent needs a restart) for the skill to take effect - Alternatively, they can read the new SKILL.md immediately to use it in the current session ### 5. Immediate Use (optional) If the user wants to use the skill right away in the current session: 1. Read the newly installed skill's SKILL.md 2. Follow its instructions to handle the original request ``` ### Technical Analysis The workflow installs third-party skills from a public registry and permits the agent to immediately follow the installed skill's instructions. Although explicit user confirmation is required, user approval does not constitute package verification or a security review. The documented process does not require: - Verification of the skill publisher or namespace. - Pinning to an immutable version. - Signature or checksum validation. - Inspection of the complete package and installation hooks. - Review of bundled scripts, permissions, or external endpoints. - Isolation or least-privilege execution. - Security review of the newly installed `SKILL.md` before following it. This creates a supply-chain trust boundary in which a malicious, compromised, or deceptively named registry package could be installed based primarily on its displayed slug and description. The immediate-use procedure increases exposure by directing the agent to treat newly acquired instructions as trusted within the current session. No malicious registry package or successful exploitation is present in the audited project. The vulnerability is the unsafe dependency acquisition and trust workflow itse ...[truncated 1991 chars]- Remediation
View remediation
