T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Mutable and Unverified External CLI Installation Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-14
Vulnerability Type: Unverified third-party dependency installation instructions
Risk Level: MediumVulnerable Code Snippet:
markdown ### Install skillhub CLI Follow [skillhub.md](https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md) to install Skillhub CLI.Technical Analysis
The skill directs users or agents to retrieve installation instructions from a mutable object hosted in an external Tencent COS bucket. The repository does not contain the referenced instructions, pin the CLI to an immutable release, or specify a cryptographic checksum or signature for the downloaded software.
Consequently, the effective installation procedure can change after this skill has been audited. If the hosting account, bucket, object, DNS resolution, or publication process is compromised, the remote document could be replaced with instructions that download and execute attacker-controlled software. This is a supply-chain trust issue; the repository itself does not demonstrate that the remote content is currently malicious.
Attack Path
- An attacker compromises or gains unauthorized publishing access to the external storage location or its release process.
- The attacker replaces
skillhub.mdwith modified installation instructions that retrieve or execute an attacker-controlled binary or script. - A user or agent follows the prerequisite documented in
SKILL.md. - The malicious installation command executes with the privileges of the invoking user.
- The installed program may then abuse its intended skill installation and self-upgrade capabilities to introduce additional untrusted components.
Impact Assessment
Successful exploitation can provide arbitrary code execution with the privileges of the user performing the installation. This may permit access to files, credentials, agent configuration, and skill ...[truncated 384 chars]
- Remediation
View remediation
Remediation Suggestions
- Store the reviewed installation procedure directly in the repository so it is covered by source review and version control.
- Pin the CLI to a specific immutable release version rather than retrieving mutable installation instructions.
- Download release artifacts only from an authenticated, trusted release channel.
- Publish and verify a SHA-256 checksum or cryptographic signature before executing or installing any downloaded artifact.
- Fail closed when integrity verification fails; do not permit an unchecked fallback download.
- Require explicit user approval before installation or self-upgrade operations.
- Disable automatic self-upgrades by default, or ensure updates use the same version pinning and signature-verification controls.
- Document the expected artifact URL, version, signer identity, checksum, and installation destination to make future audits reproducible.
