T08 · Insecure Dependencies
- Location
SKILL.md:64- Finding
Unpinned External Skill Installations Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:64,SKILL.md:171, andSKILL.md:184-186
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumThe Skill recommends installing externally maintained Skills without specifying immutable versions, release identifiers, or content hashes.
Code snippets (
SKILL.md:64):markdown No key yet? `clawhub install uday390/deepread-agent-setup` and your agent fetches one via OAuth device flow.Code snippets (
SKILL.md:171):markdown Install: `clawhub install uday390/deepread-pii`Code snippets (
SKILL.md:184-186):markdown - **deepread-ocr** — general OCR + structured extraction — `clawhub install uday390/deepread-ocr` - **deepread-form-fill** — fill application forms from parsed data — `clawhub install uday390/deepread-form-fill` - **deepread-pii** — redact for blind screening — `clawhub install uday390/deepread-pii`Technical Analysis
These commands resolve external Skill packages by mutable names. The project does not pin a reviewed version or content digest and does not include the referenced implementations, so their effective behavior cannot be established from the audited artifact.
The
deepread-agent-setupdependency is particularly sensitive because the documentation states that it conducts an OAuth device flow and obtains an API credential. If the referenced package, publisher account, distribution channel, or dependency resolution process is compromised, a later installation could differ from the version originally intended or reviewed. It could present misleading authorization instructions, capture credentials, or issue instructions that access resources available to the agent.The primary resume-processing workflow only requires document read access, network access to the declared API, and an existing API key. Installing additional Skills is therefore not a minimum-privilege requirement for ...[truncated 1407 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every external Skill to an immutable, reviewed version, commit identifier, or cryptographic content digest.
- Verify package signatures and checksums before installation, and fail closed if verification is unavailable or unsuccessful.
- Publish links to the exact source revisions used and subject those revisions to the same security review as the primary Skill.
- Make optional integrations explicitly optional and avoid automatic installation during the primary parsing workflow.
- Separate credential provisioning from document processing. Users should obtain and store credentials through a trusted, independently verified flow.
- Document the permissions, network destinations, credential access, and local file access required by each external Skill before recommending installation.
- Run installed dependencies with restricted filesystem and network access, exposing only the specific files and credentials required for their declared tasks.
- Maintain an allowlist of approved package publishers and immutable releases, with monitoring for publisher-account or dependency compromise.
