T08 · Insecure Dependencies
- Location
SKILL.md:117- Finding
Unpinned Third-Party Package Installation and Immediate Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 117
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: MediumComplete Code Snippet:
markdown This tool follows the [Agent-Native CLI Convention](https://ancc.dev). Validate with: `clawhub install ancc && ancc validate .`Technical Analysis
The documented validation procedure installs the mutable package name
anccwithout specifying an audited version, immutable digest, trusted registry identity, or signature-verification requirement. It then immediately runs the installed executable.Package names alone do not cryptographically bind an installation to the linked website or stated canonical repository. If the package source, publishing account, registry resolution process, or latest release is compromised, the installed program can contain behavior that was not present when this skill was audited.
Attack Path
- An attacker compromises the package publisher, registry entry, distribution channel, or another component involved in resolving
ancc. - The attacker publishes a modified package under the same mutable package name.
- A user or agent follows the documented command and installs the current package.
- The shell proceeds directly to
ancc validate .after installation succeeds. - Package-controlled code executes with the permissions of the invoking user and receives the project directory as its validation target.
Impact Assessment
Successful exploitation could provide code execution with the invoking user's privileges. The malicious dependency could read or modify files accessible to that account, tamper with the audited workspace, inspect locally available configuration or credentials, and potentially initiate network activity. The effective scope is limited by the operating-system permissions and sandbox restrictions applied to the invoking process.
- An attacker compromises the package publisher, registry entry, distribution channel, or another component involved in resolving
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed version and, where supported, an immutable artifact digest or repository commit.
- Document the exact trusted registry and publisher identity from which the package must be obtained.
- Require verification of a cryptographic signature or published checksum before execution.
- Separate installation and execution into distinct, user-approved steps rather than chaining them.
- Run validation in a restricted environment with minimal filesystem access, no unnecessary credentials, and network access disabled unless explicitly required.
- Explain which files the validator reads or changes and provide a non-executing verification alternative where possible.
