T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Execution of Unpinned Third-Party Installation Scripts
- Content
View full analysis
- Remediation
View remediation
``` 2. Publish and verify cryptographic checksums or signed release artifacts before executing any scripts. 3. Verify Git signatures where supported and document the expected signer identity. 4. Review the exact versions of `convert.sh` and `install.sh` before execution. 5. Avoid automatically executing downloaded scripts. Separate download, verification, and execution into explicit steps. 6. Run installation in a sandbox or restricted account with only the filesystem permissions required to install the agent definitions. 7. Document which paths the installer modifies and require confirmation before changes to `~/.openclaw/`. ]]>
