T08 · Insecure Dependencies
- Location
SKILL.md:96- Finding
Automatic Installation and Loading of an Unverified External Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 96-105
Vulnerability Type: Unverified third-party dependency installation and loading
Risk Level: MediumVulnerable Code Snippet
markdown **Loading check process** (performed on every activation): 1. Check whether the `universal-task-os` Skill is installed 2. **Not installed** → automatically install the `universal-task-os` Skill 3. **Installation succeeds** → load UTOS and execute according to this Skill's usage rules 4. **Installation fails** → fall back to **read-only reference mode**: - Allowed: consult the domain registry, task catalogs, requirements, and exemplar indexes - Denied: cross-domain orchestration, pipeline generation, and content-production tasksThe original source expresses these instructions in Chinese; the snippet above is a faithful English translation.
Technical Analysis
The Skill instructs the agent to automatically install and load the external
universal-task-osSkill whenever the dependency is absent. It does not specify:- An authoritative registry or repository
- An immutable version or commit
- A cryptographic checksum or signature
- Publisher verification
- Dependency provenance requirements
- User approval before installation
- A least-privilege execution boundary
Because the dependency is not included in the audited project, its implementation and effective privileges could not be assessed. Resolving it solely by name creates exposure to dependency confusion, namespace takeover, typosquatting within a configured Skill source, or compromise of the legitimate upstream package.
The issue is classified as an insecure dependency rather than direct remote-payload execution because the reviewed file does not specify an external URL or concrete retrieval command. Nevertheless, installation necessarily transfers trust to content outside the audited artifact.
Attack Path
- An atta ...[truncated 1345 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic installation from the activation path.
- Require explicit, informed user approval before installing any external Skill.
- Declare an authoritative registry and publisher identity for
universal-task-os. - Pin the dependency to an immutable version or commit rather than resolving the latest package by name.
- Verify a cryptographic checksum or trusted publisher signature before installation and loading.
- Audit the exact pinned dependency artifact and retain its audit record alongside this Skill.
- Reject dependencies whose source, identity, version, or integrity cannot be verified.
- Install and run the dependency with the minimum required filesystem, network, execution, and data-access permissions.
- Preserve the existing read-only fallback when the dependency is absent or verification fails.
- Record dependency installation and verification events in an auditable log without exposing sensitive data.
