T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Executable Downloads Lack Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23-32
Vulnerability Type: Unverified third-party executable download
Risk Level: MediumCode Snippet:
markdown 1. **Download and Install Everything:** - Visit the official Everything website: https://www.voidtools.com/downloads/ - Download and install the latest version of Everything - Ensure that the "ES Command Line Tool" option is selected during installation **Direct Download Links:** **Everything 1.4.1 (Stable Version):** - Portable ZIP: https://www.voidtools.com/Everything-1.4.1.1032.x64.zip - Installer: https://www.voidtools.com/Everything-1.4.1.1032.x64-Setup.exeTechnical Analysis
The skill directs users to download and execute third-party installers or portable binaries but provides no pinned cryptographic hashes or instructions to verify the executable's Authenticode signature. HTTPS protects data in transit under normal conditions, but it does not independently verify that the downloaded artifact is the exact artifact reviewed or intended by the skill author.
If the vendor's distribution infrastructure, DNS resolution, TLS trust chain, or linked artifact is compromised, a substituted executable could run arbitrary code. The direct links use the stated vendor's HTTPS domain, so the documentation does not establish malicious intent or an active compromise; the issue is the absence of artifact-level verification.
Attack Path
- An attacker compromises or successfully impersonates an element of the executable delivery path.
- The installer or ZIP referenced by the skill is replaced with a modified artifact.
- A user follows the skill instructions and downloads the artifact without checking a pinned hash or trusted publisher signature.
- The user launches the installer or extracted executable.
- The substituted binary executes attacker-controlled code with the privileges of the i ...[truncated 529 chars]
- Remediation
View remediation
Remediation Suggestions
- Publish and pin a SHA-256 digest for every supported installer and ZIP artifact.
- Instruct users to compare the downloaded file's digest against the pinned value before execution.
- Require Authenticode verification and identify the expected publisher certificate subject.
- Reject artifacts with an invalid, missing, expired, or unexpected publisher signature.
- Prefer a reputable Windows package manager where package identity and version can be pinned and independently validated.
- Avoid recommending an unpinned “latest version” when reproducible review is required.
- Periodically update versions, hashes, and expected signing-certificate information through a controlled review process.
