T08 · Insecure Dependencies
- Location
README.md:27- Finding
Unpinned and Unverified External Knowledge Database
- Content
View full analysis
The database is at `data/knowledge_new_fixed.db.zip` (29 MB) and is > automatically extracted during the first query. > - **ClawHub installation**: The database is not included in the published > package. Download it from GitHub Releases and place it in `data/`. ``` ### Technical Analysis The installation instructions require users to retrieve `knowledge_new_fixed.db.zip` separately from the author's GitHub Releases page. They do not identify an immutable release version, expected SHA-256 digest, digital signature, or trusted key. The database is a functional third-party component of the Skill. Its `core_definition`, `mechanism`, and `musk_insight` fields are returned to the Agent and used to construct responses. Consequently, the separately downloaded database affects the Skill's effective behavior even though it is not executable code. If the repository, release account, asset, or delivery path is compromised, an attacker could substitute a modified archive. The Skill would accept and process it without verifying provenance or integrity. Malicious database records could supply misinformation or text designed to manipulate the Agent. The absence of the database from the audited package also means its actual contents were outside this audit's coverage. This behavior is required only because the database exceeds the package size limit. Downloading a data component is compatible with the declared functionality, but accepting an unversioned ...[truncated 1342 chars]- Remediation
View remediation
