T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party Package Installation Through a Mutable External Catalog
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13–26, 32–38, 58–64, and 69–81
Vulnerability Type: Supply-chain exposure caused by unpinned dependencies and a mutable external package catalog
Risk Level: HighVulnerable Code
markdown ## Quick Start ```bash # Install the CLI Hub package manager pip install cli-anything-hub # Browse all available CLIs cli-hub list # Search by category or keyword cli-hub search image cli-hub search "3d modeling" # Install a CLI cli-hub install gimptext ```markdown ## Live Catalog **URL**: [`https://clianything.cc/SKILL.txt`](https://clianything.cc/SKILL.txt) The catalog is auto-updated and provides: - Full list of available CLIs organized by category - One-line `cli-hub install` commands for each toolmarkdown `cli-hub` is a lightweight wrapper around `pip`. When you run `cli-hub install gimp`, it installs a separate Python package (`cli-anything-gimp`) with its own CLI entry point (`cli-anything-gimp`). Each CLI is an independent pip package — `cli-hub` simply resolves names from the registry and tracks installs. ## How to Use 1. **Install cli-hub**: `pip install cli-anything-hub` 2. **Find your tool**: `cli-hub search <keyword>` or `cli-hub list -c <category>` 3. **Install**: `cli-hub install <name>` (installs the `cli-anything-<name>` pip package)markdown ## Example Workflow ```bash # Install the hub pip install cli-anything-hub # Find what you need cli-hub search video # Install it cli-hub install kdenlive # Use it with JSON output cli-anything-kdenlive --json project create --name my-projecttext ### Technical Analysis The Skill instructs an agent to install `cli-anything-hub` directly from the package index without specifying an audited version or cryptographic hash. It then delegates the selection and installation of additional independent ...[truncated 2534 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
cli-anything-huband every approved downstream package to an explicitly reviewed version. - Require cryptographic hashes for downloaded artifacts, such as through a locked requirements file and pip's
--require-hashesoption. - Replace mutable catalog resolution with a versioned, signed, and reviewable manifest.
- Maintain an allowlist mapping approved CLI names to exact package names, versions, artifact hashes, and trusted sources.
- Verify package provenance and signatures where supported, and retain software-bill-of-materials and audit metadata.
- Review package source code, build configuration, dependencies, and entry points before adding a package to the allowlist.
- Prefer an internally controlled package mirror containing only reviewed artifacts rather than resolving arbitrary current releases from a public index.
- Install and execute packages in an isolated environment or disposable sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and no administrative privileges.
- Separate package discovery from installation and require explicit approval before executing an installation command recommended by the remote catalog.
- Document safe upgrade procedures so new package versions are reviewed and their hashes updated before deployment.
- Pin
