T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party Repository Used for Setup and Build Instructions
- Content
View full analysis
[flags] ``` ``` `references/command-reference.md:5-11`: ```markdown Tool repository: https://github.com/mekedron/wolt-cli Open the repository for setup/build details, then use the local binary: ```bash wolt [flags] ``` ``` ### Technical Analysis The Skill delegates setup and build instructions to the current contents of a mutable third-party GitHub repository. It does not pin a reviewed release, tag, or commit and provides no checksum or signature verification procedure. Consequently, the software and installation instructions used at execution time may differ from those that existed when the Skill was reviewed. Compromise of the repository, its maintainer account, its release process, or one of its transitive dependencies could introduce attacker-controlled build or installation behavior. The reviewed package does not itself download or execute remote code, so this is classified as an insecure dependency and supply-chain weakness rather than confirmed remote payload execution. ### Attack Path 1. An attacker compromises the linked repository, its maintainer account, release artifacts, or dependency chain. 2. The attacker changes the setup instructions or source code to include malicious commands. 3. A user or Agent follows the Skill's direction to open the repository and use its current setup or build instructions. 4. The altered component is built or installed locally. 5. Malicious code executes with the privileges of the user performing the installation or running the CLI. ### Impact Assessment Success ...[truncated 434 chars]- Remediation
View remediation
