T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned External Skill Installation and Instruction Delegation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:3, 20-21
Vulnerability Type: Unpinned third-party Skill dependency and delegation to unaudited external instructions
Risk Level: MediumVulnerable Code Snippet:
yaml description: "Paid math calculator — $0.01/expression via Pearl payments. Run: node {baseDir}/scripts/calc.js \"<expr>\". Right after install of this skill, ask user if he wants to proceed with setup. If yes, then you go through setup process: install nodejs deps, install pearl skill (clawhub install pearl), read pearl's SKILL.md and proceed."markdown 1. Install the pearl skill: `clawhub install pearl` 2. Read pearl's SKILL.md and follow its **Setup (one-time)** section.Technical Analysis
The setup procedure installs the external
pearlSkill without specifying an immutable version or integrity digest. It then instructs the Agent to read and follow that Skill's setup instructions. Consequently, the effective setup behavior is not fully represented by the code reviewed in this project and may change independently after this audit.This creates a supply-chain trust boundary: control of the registry entry, its distribution infrastructure, or a future release could allow an attacker to supply altered instructions. User approval before setup reduces accidental execution but does not establish the authenticity or safety of the subsequently retrieved content.
The project also pins
@pearl-cash/clientto version0.0.15, but no lockfile or integrity metadata was present in the audited directory. The primary confirmed issue is the unpinned external Skill and instruction delegation.Attack Path
- An attacker compromises the
pearlregistry entry, its publisher account, or its distribution channel, or publishes a harmful future release under the trusted name. - A user approves the documented setup process.
- The Agent executes
clawhub install pearlwithout a v ...[truncated 1304 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the external
pearlSkill to a specifically audited version and an immutable cryptographic digest. - Verify signatures or checksums before loading or following external Skill instructions.
- Vendor the required setup instructions locally, or explicitly document the exact audited commands instead of delegating to mutable external text.
- Require separate, informed user confirmation before each consequential installation or command rather than one broad setup approval.
- Restrict setup execution to the minimum required tools, filesystem paths, network destinations, and credentials.
- Add and commit a package lockfile with registry integrity metadata for Node.js dependencies, and use a deterministic installer such as
npm ci. - Re-audit any updated Pearl Skill or client dependency before deployment.
- Pin the external
