T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party GitHub Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Unpinned dependency from a mutable remote repository
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"📝","requires":{"bins":["qmd"]},"install":[{"id":"node","kind":"node","package":"https://github.com/tobi/qmd","bins":["qmd"],"label":"Install qmd (node)"}]}}Technical Analysis
The installation configuration references a GitHub repository URL without pinning an immutable commit, versioned release, or verified artifact checksum. Consequently, the code installed from this location can change after the Skill has been reviewed.
The dependency's executable source is not included in the audited artifact, so its implementation and transitive dependencies could not be verified. Although the audit found no evidence that the current upstream project is malicious, relying on a mutable source creates a supply-chain risk. Compromise of the upstream repository, its publishing workflow, or its dependency chain could cause future installations to receive altered code.
Attack Path
- An attacker compromises the referenced repository, a maintainer account, its release workflow, or a relevant transitive dependency.
- The attacker modifies the code resolved through the mutable GitHub URL.
- A user installs the Skill's required
qmdexecutable using the declared installation configuration. - The altered dependency is installed and subsequently executed when the Agent invokes
qmd. - The malicious process operates with the privileges of the user running the Agent and can attempt to access resources available to that user.
Impact Assessment
Successful exploitation could result in arbitrary code execution with the installing or invoking user's privileges. Because the documented tool indexes and retrieves local files, uses a cache under
~/.cache/qmd, communicates with an Ollama endpoint, and supports ...[truncated 416 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an immutable, reviewed commit hash or a specific signed release rather than a mutable repository URL.
- Verify downloaded artifacts with a published SHA-256 checksum or supported package-integrity mechanism before installation.
- Prefer a trusted package registry that supports immutable versions, provenance attestations, and integrity metadata.
- Lock all transitive dependency versions and use reproducible installation procedures.
- Enable repository branch protection, signed tags or commits, protected release workflows, and multi-factor authentication for maintainers.
- Perform dependency and source-code scanning on the exact pinned revision before approving updates.
- Run the executable with least privilege and restrict its filesystem and network access to only the documents, cache directory, Ollama endpoint, and MCP interfaces required for operation.
