T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Third-Party Go Dependencies Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:18-20,SKILL.md:43, andreferences/mocking.md:201-205
Vulnerability Type: Mutable and unverified third-party dependencies
Risk Level: MediumVulnerable Code
SKILL.md:18-20:yaml install: - kind: go package: github.com/cweill/gotests/gotests@latestSKILL.md:43:markdown - gotests: `go install github.com/cweill/gotests/gotests@latest`references/mocking.md:201-205:markdown Install clockwork: ```bash go get github.com/jonboulle/clockworktext ### Technical Analysis The skill directs users or agents to obtain third-party Go components without pinning them to reviewed, immutable versions. The `@latest` selector explicitly resolves to the version considered current at installation time. The versionless `go get` instruction similarly leaves dependency resolution to the state of the upstream module and the target project's module configuration at execution time. As a result, the code installed or incorporated into a project can differ from the code present when this skill was audited. This weakens reproducibility and creates a supply-chain trust boundary around upstream repositories, maintainers, module proxies, and transitive dependencies. The `gotests` dependency is particularly relevant because it installs an executable that the skill allows the agent to invoke. A malicious version could therefore run with the permissions of the user executing the skill. A compromised `clockwork` release could be compiled into generated test code and execute when affected tests or related binaries run. There is no evidence that the named upstream projects or their current releases are malicious. The vulnerability is the unsafe use of mutable dependency references. ### Attack Path 1. An attacker compromises an upstream maintainer account, repository, release process, module path, or transitive depende ...[truncated 1294 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin
goteststo a specifically reviewed release rather than using@latest:bash go install github.com/cweill/gotests/gotests@vX.Y.Z -
Pin
clockworkto an explicit reviewed release:bash go get github.com/jonboulle/clockwork@vX.Y.Z -
Record the selected versions in the skill metadata and documentation so installation behavior is consistent.
-
Review direct and transitive dependencies before updating pinned versions. Validate the module path, release provenance, maintainer history, and unexpected dependency changes.
-
Retain and verify
go.sumentries in target projects. Where appropriate, use a trusted Go module proxy and checksum database rather than bypassing checksum verification. -
Test dependency upgrades in an isolated environment before making them the skill default.
-
Run installed development tools with least privilege. CI jobs that execute code-generation tools should receive only the credentials and filesystem access required for that job.
-
