T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Untrusted Remote Installation Commands Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15-17andSKILL.md:60-69
Vulnerability Type: Unvalidated third-party installation instructions
Risk Level: MediumVulnerable Code Snippet:
markdown 1. User describes a task → call **recommend** → get best skill + alternatives with reasons 2. User wants to install → provide the `install` command from the response 3. User wants details → call **detail** for full analysismarkdown ## Install Users can install skills via: - `clawhub install <slug>` (official ClawHub CLI) - `skillscope install <slug>` (China mirror, `pip install skillscope`) To get installable files via API: ```bash curl "https://skillscope.cn/api/v1/install/weather/files"text ### Technical Analysis The skill instructs the agent to provide an installation command received from an external recommendation service. It does not require the command, package identifier, resolved repository, publisher, arguments, version, signature, or checksum to be validated before presenting the command to the user. This creates an insecure dependency and supply-chain trust boundary. The effective package selected for installation can change independently of the reviewed `SKILL.md` file. A compromised API, poisoned catalog record, malicious publisher, package-name collision, or dependency takeover could cause a recommendation to resolve to attacker-controlled content. The additional instruction to use `pip install skillscope` is unpinned and does not specify an integrity hash. Consequently, the installed artifact depends on the package registry's current resolution state rather than a version reviewed with this skill. ### Attack Path 1. An attacker compromises the external recommendation service, poisons a catalog entry, takes over a listed package, or publishes a deceptively named dependency. 2. A user asks the agent to find a skill for a supported task. 3. The ...[truncated 1247 chars]- Remediation
View remediation
Remediation Suggestions
- Do not accept or relay arbitrary command strings from the remote API. Require the API to return structured identifiers such as package name, registry, publisher, repository URL, version, and integrity digest.
- Construct installation commands locally from validated fields using a strict allowlist of supported installers and arguments.
- Resolve each recommendation to its canonical source and show the user the publisher, repository, requested permissions, version, and security-review status.
- Pin packages and skills to reviewed versions or immutable commit identifiers.
- Verify cryptographic signatures or trusted checksums before installation.
- Detect package-name collisions, typosquatting, unexpected publisher changes, and repository ownership transfers.
- Require explicit user confirmation after displaying the exact source and security implications.
- Install third-party skills in a sandbox with least privilege and restricted filesystem, credential, and network access.
- Replace the unpinned
pip install skillscopeinstruction with a verified, version-pinned installation procedure using hashes.
