T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned and Unreviewed Third-Party Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31–34, 81–86, and 129–133
Vulnerability Type: Supply-chain exposure through unpinned remote packages and skills
Risk Level: MediumVulnerable Code
bash # Search skills.sh npx skills find [query] # Install from skills.sh npx skills add <owner/repo@skill> -g -ybash # From skills.sh: npx skills add vercel-labs/agent-skills@react-best-practices -g -ybash # From ClawHub: clawhub install <skill-name>text 1. Search: npx skills find react testing 2. Check leaderboard: react-best-practices has 185K installs 3. Verify: From vercel-labs, high installs, maintained 4. Recommend: "react-best-practices provides React testing patterns (185K installs)" 5. Install: npx skills add vercel-labs/agent-skills@react-best-practices -g -yTechnical Analysis
The documented workflow invokes the
skillspackage throughnpxwithout pinning the CLI to a reviewed version. It also installs remotely sourced skills globally with-gand suppresses interactive confirmation with-y. The ClawHub workflow similarly accepts a skill name without requiring a fixed version, digest, signature, or prior inspection of the retrieved files.Consequently, the content executed or installed at audit time is not guaranteed to be the same content that was previously reviewed. Repository reputation, installation counts, GitHub stars, and automated security scans are useful signals, but they do not establish package integrity or protect against maintainer compromise, account takeover, dependency confusion, typosquatting, or a malicious update.
Attack Path
- An attacker publishes a similarly named package or skill, compromises a legitimate publisher, or introduces a malicious update into an existing remote source.
- The malicious entry appears in search results or retains the reputation and installation statistics ...[truncated 1377 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI and every installed skill to an exact, reviewed version rather than relying on the latest remotely available release. - Verify the publisher identity, canonical repository URL, release provenance, and package ownership before downloading anything.
- Require cryptographic signatures or trusted checksums and validate them before installation.
- Download the artifact without executing it, inspect all included files and lifecycle hooks, and compare the reviewed digest with the artifact that will be installed.
- Remove
-yso that installation requires explicit user confirmation after displaying the resolved source, version, and requested changes. - Avoid
-g; install into an isolated, least-privileged project environment or disposable sandbox. - Execute package and skill inspection with network, filesystem, process, and credential access restricted.
- Require explicit approval before invoking any newly installed skill, especially one containing shell commands or instructions involving secrets.
- Treat popularity metrics and automated scans only as supplementary evidence, not as substitutes for version pinning and integrity verification.
- Pin the
