T08 · Insecure Dependencies
- Location
SKILL.md:214- Finding
Unpinned Third-Party Executable Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 214–222
Vulnerability Type: Supply-chain risk from mutable and unverifiable third-party dependencies
Risk Level: MediumVulnerable Code
bash # Via Go go install github.com/pjtf93/weathercli/cmd/weathercli@latest # Or download binary from releases # https://github.com/pjtf93/weathercli/releasesTechnical Analysis
The installation guidance uses the mutable
@latestselector to retrieve and compile third-party code that is not included in the audited project. The alternative release-download guidance similarly provides no fixed version, checksum, digital signature, or verification procedure.Because dependency contents are resolved at installation time, the executable ultimately installed and run may differ from the implementation that the skill author reviewed or described. Static review of
SKILL.mdtherefore cannot verify that the executable only performs the documented geocoding and Open-Meteo requests.Exploitation requires control of, or malicious publication through, the referenced upstream repository or release channel. There is no evidence in the audited artifact that the named upstream project is currently malicious.
Attack Path
- An attacker compromises the upstream repository, maintainer account, build pipeline, or release account, or otherwise causes a malicious version to become the version resolved as
latest. - A user or agent follows the skill's installation instructions.
go install ...@latestretrieves and compiles the attacker-controlled source, or the user downloads a substituted release binary.- The resulting
weathercliexecutable is invoked for a weather request. - The malicious executable runs with the privileges and environmental access of the invoking user or agent.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing or invoking us ...[truncated 526 chars]
- An attacker compromises the upstream repository, maintainer account, build pipeline, or release account, or otherwise causes a malicious version to become the version resolved as
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a reviewed, immutable version or commit identifier. - Publish the expected cryptographic checksum for each supported release artifact and require verification before execution.
- Prefer signed releases and document signature verification against a trusted maintainer key or identity.
- Pin transitive Go dependencies through a reviewed
go.modandgo.sumin auditable source. - Avoid automatic installation. Require explicit user approval before downloading or executing third-party software.
- Where feasible, vendor the reviewed source or distribute reproducible builds so users can confirm that binaries correspond to audited code.
- Run the utility with least privilege and a restricted environment, filesystem view, and network policy limited to documented weather-service endpoints.
- Replace
