T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Mutable, Unverified Registry Data Controls Installation Trust Decisions
- Content
View full analysis
Score: /100 Verdict: Scanned: Registry: https://credence.securingthesingularity.com/registry.html ``` Then give your recommendation: - **APPROVED (90+):** Safe to install. Proceed. - **CONDITIONAL (70-89):** Mention the score and suggest the user review the registry page for details before installing. - **FLAGGED (40-69):** Warn the user. Do not install without explicit confirmation. - **REJECTED (0-39):** Do not install. Explain that Credence found serious issues. ``` ### Technical Analysis The skill obtains security ratings from an external file on the mutable `main` branch of a third-party GitHub repository. It does not require a pinned commit, cryptographic signature, trusted digest, or independently verifiable attestation before using the returned data. HTTPS protects data in transit but does not protect against compromise of the registry repository, its maintainer account, GitHub publishing credentials, or the registry-generation process. An attacker controlling any of those elements could modify an existing record or add a malicious server with an `APPROVED` score. The instructions then treat a score of 90 or greater as sufficient to state that a server is safe and to proceed. Consequently, mutable external data functions as an authorization input for a security-sensitive installation decision. ...[truncated 1382 chars]- Remediation
View remediation
