T08 · Insecure Dependencies
- Location
scripts/install_skill.sh:31- Finding
Forced Installation of Security-Flagged Third-Party Skills
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_skill.sh:31, with security-warning retry behavior atscripts/install_skill.sh:43-47
Vulnerability Type: Supply-chain safety control bypass
Risk Level: HighVulnerable Code
bash OUTPUT=$(clawhub install "$SKILL_NAME" --force 2>&1)The script also detects the
flagged as suspiciouswarning at lines 43-47 but continues retrying rather than terminating the installation.Technical Analysis
The installer unconditionally passes
--forcetoclawhub installfor every user-provided skill. This bypasses the package registry's confirmation or safety barrier without requiring informed user approval.The script explicitly recognizes when a skill has been flagged as suspicious, but its response is to wait and retry. Consequently, a registry warning does not establish a fail-closed security boundary. Because ClawHub skills may contain executable scripts or agent instructions, forcibly installing an untrusted skill creates a supply-chain path through which attacker-controlled content can enter the agent environment.
The skill name is quoted correctly, so no direct shell metacharacter injection was identified through the
SKILL_NAMEargument. The risk instead arises from trusting and forcibly installing the selected third-party package.Attack Path
- An attacker publishes, compromises, or identifies a malicious ClawHub skill.
- ClawHub marks the skill as suspicious or otherwise requires explicit confirmation.
- The attacker persuades a user or agent to invoke this installer with that skill name.
- The script executes
clawhub installwith--force, bypassing the normal confirmation barrier. - If the registry returns a suspicious-package warning, the script continues retrying for up to approximately 30 minutes instead of stopping.
- If installation succeeds, attacker-controlled skill instructions or scripts are introduced into t ...[truncated 1074 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove unconditional use of
--forceand perform normal installation by default. - Treat a
flagged as suspiciousresponse as a terminal security failure rather than a retryable operational error. - Require explicit, interactive user approval before any override, and display the exact skill name, publisher, version, source, integrity information, warning, and requested capabilities.
- Do not permit an autonomous agent to approve its own security override.
- Restrict installations to an allowlist of reviewed publishers and skills where practical.
- Pin approved package versions and verify cryptographic hashes or signatures before installation.
- Separate transient errors, such as rate limiting, from permanent and security-related errors. Retry only well-defined transient failures.
- Install and inspect untrusted skills in a sandbox with minimal filesystem, process, network, credential, and tool permissions before allowing normal use.
- Update
SKILL.mdso that it no longer directs the agent to force installation or retry suspicious packages and accurately documents which failures terminate execution.
- Remove unconditional use of
