T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unverified Third-Party Executable Download and System-Wide Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35-39
Vulnerability Type: Unverified third-party dependency installation
Risk Level: Mediumbash # Install Gog from latest release cd /tmp curl -L -o gogcli_0.12.0_linux_amd64.tar.gz https://github.com/steipete/gogcli/releases/download/v0.12.0/gogcli_0.12.0_linux_amd64.tar.gz tar -xzf gogcli_0.12.0_linux_amd64.tar.gz install -m 0755 gog /usr/local/bin/gogTechnical Analysis
The Skill downloads a precompiled executable archive from a third-party GitHub repository, extracts it, and installs the resulting executable into
/usr/local/bin. Although the release version is pinned tov0.12.0, the instructions do not verify a cryptographic checksum or trusted release signature. Version pinning alone does not establish artifact integrity or publisher authenticity.The process also operates directly in the shared
/tmpdirectory rather than a newly created private temporary directory. The predictable archive filename and extracted executable name increase exposure to local file-race or replacement attacks between download, extraction, and installation.Installation into
/usr/local/binnormally requires elevated privileges and places the executable on the system-wide command path. This exceeds the minimum privileges necessary to provide Gmail access when a user-local installation directory could be used instead.The risk is amplified because the installed program subsequently processes Google OAuth client material, authorization callbacks, stored tokens, the keyring password, and Gmail data.
Attack Path
Supply-chain attack path:
- An attacker compromises the referenced GitHub account, release artifact, or upstream build and publishes a malicious archive at the pinned release URL.
- A user follows the Skill instructions and downloads the archive without validating a checksum or signature.
- The malicious
gogexecutable is extrac ...[truncated 1543 chars]
- Remediation
View remediation
Remediation Suggestions
- Publish and pin a trusted SHA-256 digest for the exact archive, then verify it before extraction:
bash printf '%s %s\n' 'EXPECTED_SHA256' 'gogcli_0.12.0_linux_amd64.tar.gz' | sha256sum --check - - Verify a cryptographic release signature from a separately established trusted publisher key when signed releases are available.
- Prefer an official, organization-controlled package repository or other authenticated distribution channel.
- Use a private temporary directory created with
mktemp -d, apply restrictive permissions, and remove it after installation. - Inspect archive entries before extraction and reject absolute paths, parent-directory traversal, links, and unexpected files.
- Avoid system-wide installation unless it is operationally required. Install the verified executable into a user-owned directory such as
~/.local/binto avoid unnecessary privilege elevation. - If system-wide installation is required, separate artifact verification from the narrowly scoped privileged installation step and install only the exact verified file.
- Document the binary's publisher, expected digest, required Gmail OAuth scopes, and update procedure so future upgrades do not silently reintroduce unverified downloads.
- Publish and pin a trusted SHA-256 digest for the exact archive, then verify it before extraction:
