T08 · Insecure Dependencies
- Location
SKILL.md:90- Finding
Unpinned External Plugin Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 90–92
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
markdown - Install and enable the plugin with `hermes plugins install Xquik-dev/hermes-tweet --enable`.Technical Analysis
The skill instructs users to retrieve and immediately enable the external
Xquik-dev/hermes-tweetplugin without specifying an immutable version, commit hash, checksum, or trusted signature. Consequently, the code installed later may differ from the code that was originally reviewed.The external plugin is not included in the audited project, so its implementation and integrity cannot be verified from this artifact. Enabling it immediately after retrieval expands the supply-chain exposure because downloaded plugin code may execute within Hermes with access to configured network and tool capabilities.
This is an insecure dependency practice rather than evidence that the current upstream plugin is malicious.
Attack Path
- An attacker compromises the upstream repository, its distribution mechanism, or a maintainer account.
- The attacker modifies the plugin revision resolved by the unpinned repository reference.
- A user follows the documented installation command.
- Hermes downloads the changed plugin and enables it immediately through
--enable. - The altered plugin executes in the Hermes runtime.
- Depending on runtime configuration, it may gain access to authenticated Xquik reads and approved action capabilities.
Impact Assessment
A compromised plugin could operate within the privileges granted to the Hermes plugin runtime. The potential scope includes:
- Access to authenticated Xquik API functionality when
XQUIK_API_KEYis configured. - Unauthorized observation or manipulation of data handled by plugin tools.
- Abuse of X account or workflow operations when action tooling is enabled.
- Compromise of the confidentiality and ...[truncated 227 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to an immutable, reviewed release or commit rather than a mutable repository reference.
- Publish and verify a cryptographic checksum or signature for the exact plugin artifact before enabling it.
- Separate installation from activation so integrity and provenance checks occur before plugin code is loaded.
- Record the reviewed plugin version and source commit in
SKILL.md. - Prefer a trusted package registry with immutable releases and provenance attestations.
- Vendor the reviewed plugin when practical, or include it in the audit scope.
- Retain the existing least-privilege controls: keep action tooling disabled by default, require explicit per-operation approval, and limit runtime credentials and network permissions.
