T08 · Insecure Dependencies
- Location
SKILL.md:94- Finding
Unpinned Third-Party Skill Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 94-106
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
markdown Install: `clawhub install uday390/deepread-pii` ## Tips - **Photos work** — vision AI handles phone captures, but flat, glare-free, well-lit images extract best. - **Expect `needs_review`** on worn cards/glare — that's the feature; verify those manually. - **Don't store more than you need** — extract the minimum fields and redact the source. ## Related DeepRead Skills - **deepread-form-fill** — fill onboarding forms from extracted ID data — `clawhub install uday390/deepread-form-fill` - **deepread-pii** — redact identity documents — `clawhub install uday390/deepread-pii` - **deepread-ocr** — general extraction — `clawhub install uday390/deepread-ocr`Technical Analysis
The documentation directs users to install third-party ClawHub skills by publisher and package name without specifying an immutable version, commit hash, checksum, signature, or other integrity constraint. Consequently, the package installed later may differ from the package that was reviewed when this skill was published.
This creates a supply-chain risk because control of a referenced publisher account or registry package would allow an attacker to replace a dependency with modified instructions, scripts, or configuration. The project does not instruct users to verify package provenance, inspect requested permissions, or review the dependency before installation.
Attack Path
- An attacker compromises the ClawHub publisher account, registry entry, or distribution process for one of the referenced skills.
- The attacker publishes a modified package under the same mutable package name.
- A user follows an installation command from
SKILL.md. - ClawHub resolves the unpinned name to the attacker-controlled package.
- The malicious pac ...[truncated 1027 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every referenced skill to an immutable, reviewed version or content digest.
- Publish and verify cryptographic checksums or signatures for dependency artifacts.
- Verify publisher identity and package provenance before recommending installation.
- Document the permissions, network destinations, environment variables, and local resources required by each dependency.
- Require security review of dependency updates before changing pinned versions.
- Clearly mark related skills as optional and avoid making their installation a prerequisite unless necessary.
- Where pinning is unsupported, instruct users to inspect the resolved package contents and permissions before installation.
