T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned and Unverified Third-Party Skill Installation
- Content
View full analysis
") ``` ### Technical Analysis The initialization instructions install eight third-party Skills using package names alone. They do not specify immutable versions, content hashes, verified publisher identities, trusted registry constraints, or an approval step that reviews the resolved package contents. Because these dependencies are not included in the audited project, their effective behavior cannot be assessed from this repository. Name-only resolution allows the content associated with a dependency to change after this Skill has been reviewed. This creates a supply-chain risk if a registry account is compromised, a package is transferred or replaced, dependency resolution reaches an unintended source, or a malicious package is published under a confusing identity. The shell installer repeats the same dependency names in `scripts/install_deps.sh:10-19`, confirming that the dependencies are treated as mutable named components rather than pinned artifacts. ### Attack Path 1. An attacker compromises the publisher or registry entry for one of the eight named Skills, or causes dependency resolution to select an attacker-controlled package. 2. A user triggers the enterprise-service initialization workflow. 3. The workflow calls `skillhub_install` with only the mutable Skill name. 4. The installation mechanism resolves and installs the attacker-controlled version without verifying an expected version, hash, or publisher identity. 5. The malicious dependency subsequently executes when invoked and operates with whatever filesystem, ...[truncated 752 chars]- Remediation
View remediation
