T08 · Insecure Dependencies
- Location
SKILL.md:163- Finding
Mutable Remote Setup Guide Creates an Unreviewed Supply-Chain Trust Boundary
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 163-166
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumtext If a channel needs setup (cookies, Docker, etc.), fetch the install guide: https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md User only provides cookies. Everything else is your job.Technical Analysis
The Skill delegates channel setup to a remotely hosted document on the mutable
mainbranch. The retrieved document is not pinned to a reviewed commit, version, or integrity digest. Consequently, its effective instructions can change after this Skill package has been audited.The broad instruction that everything other than supplying cookies is the agent's responsibility increases the likelihood that future remote instructions will be followed without a separate security review. The referenced setup scope expressly includes cookies and Docker, which may involve sensitive authentication material, dependency installation, container execution, filesystem access, or elevated operations.
This is a supply-chain weakness rather than evidence that the current remote guide is malicious. The risk arises if the upstream repository, maintainer account, hosting path, or mutable guide is compromised or changed unsafely.
Attack Path
- An attacker compromises the upstream repository or an authorized maintainer account, or otherwise causes malicious instructions to be added to
docs/install.mdon themainbranch. - A user requests configuration of a channel that requires setup.
- Following
SKILL.md, the agent retrieves the current remote installation guide. - The modified guide instructs the agent to install an unsafe dependency, execute a command, launch a malicious container, or mishandle supplied cookies.
- If the agent follows those instructions without validation or user approval, attacker-controlled actions execute with the permis ...[truncated 825 chars]
- An attacker compromises the upstream repository or an authorized maintainer account, or otherwise causes malicious instructions to be added to
- Remediation
View remediation
Remediation Suggestions
- Pin the installation guide to a reviewed immutable commit rather than the mutable
mainbranch. - Record and verify a cryptographic digest for downloaded setup material.
- Prefer vendoring the reviewed setup instructions into the Skill package so they are covered by the same audit.
- Treat remotely retrieved documentation as untrusted data, not automatically executable instructions.
- Require explicit user confirmation before installing dependencies, starting containers, changing proxy settings, handling cookies, or running privileged commands.
- Display the exact proposed commands and their security implications before execution.
- Run setup operations with least privilege in an isolated environment, with narrowly scoped filesystem and network access.
- Never transmit authentication cookies to destinations that have not been explicitly disclosed and approved.
- Pin the installation guide to a reviewed immutable commit rather than the mutable
