T08 · Insecure Dependencies
- Location
SKILL.md:136- Finding
Unpinned and Unverifiable Executable Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:136-142andSKILL.md:313
Vulnerability Type: Supply-chain dependency ambiguity
Risk Level: HighVulnerable Code
bash python wa_batch_sender.py \ --store ~/.wacli \ --recipients "contacts.json" \ --message "..." \ --rate_limit 3 \ --retry 3 \ --dry_run falseEnglish rendering of the dependency declaration at line 313:
text wacli | CLI tool | Required | Install through a package manager or compile from sourceTechnical Analysis
The Skill directs the Agent to execute
wa_batch_sender.py, but the audited package contains onlySKILL.md; the referenced Python script is not included. Consequently, script resolution depends on the Agent's current working directory and local environment.The required
wacliexecutable is similarly identified only by a generic command name. The documentation provides no canonical package identifier, trusted repository URL, pinned version or commit, cryptographic checksum, or signature-verification procedure. The instruction to install it through an unspecified package manager or compile it from unspecified source leaves dependency provenance unresolved.These conditions create dependency-confusion, name-collision, and local executable-substitution risks. A malicious file with the expected script name or a malicious package exposing the expected CLI name could be selected without an obvious change to the documented command.
Attack Path
- An attacker publishes a misleading or compromised package that installs an executable named
wacli, or places a maliciouswa_batch_sender.pyin a directory from which the Agent runs the documented command. - The user or Agent follows the Skill's installation or execution instructions without a canonical source or integrity information.
- Python resolves and executes the attacker-controlled local script, or the shell resolves the malicio ...[truncated 917 chars]
- An attacker publishes a misleading or compromised package that installs an executable named
- Remediation
View remediation
Remediation Suggestions
- Include
wa_batch_sender.pyin the Skill package and subject it to source review. - Invoke bundled scripts through a validated, absolute Skill-relative path rather than relying on the current working directory.
- Document the canonical publisher, repository, and exact package identifier for
wacli. - Pin dependencies to an immutable version or commit and publish expected cryptographic checksums.
- Require signature or checksum verification before installation and execution.
- Resolve the executable path explicitly and verify its provenance before invoking it.
- Run the dependency in a least-privilege sandbox with access restricted to explicitly approved input and output directories.
- Prevent the process from reading unrelated environment variables, credential stores, and filesystem locations.
- Include
