T08 · Insecure Dependencies
- Location
SKILL.md:72- Finding
Unpinned External CLI Dependency from a Mutable Source
- Content
View full analysis
``` Related dependency metadata at lines 244–250 does not identify the required CLI as a third-party dependency: ```markdown ### 第三方依赖 | 依赖项 | 类型 | 是否必需 | 获取方式 | |:-------|:-----|:---------|:---------| | LLM API | API | 必需 | 由Agent内置LLM提供 | ### API Key 配置 - 本Skill基于Markdown指令,无需额外API Key(除内容中明确标注的外部API) ``` ### Technical Analysis The skill requires an external `linear` executable and grants the agent access to the `exec` tool, but it does not pin the CLI to a reviewed version, immutable commit, checksum, signature, or other verifiable artifact. Instead, installation is delegated to instructions hosted in a mutable personal GitHub repository. The installation URL does not itself execute code, and the audited file contains no automatic download command. However, users or agents following the prerequisite instructions may install executable code whose content can change after this skill has been reviewed. The dependency metadata compounds this issue by listing only the LLM API and omitting both the required Linear CLI and the associated Linear authentication requirement. This creates a supply-chain trust gap: subsequent commands documented by the skill treat whichever `linear` executable appears first on `PATH` as trusted. If the referenced repository, maintainer account, installation documentation, package publication channel, or release artifact is compromised, an attacker can substitute malicious executable content. ### Attack Path 1. An attacker compromises the referenced repository, its maintainer account, a release artifact, or the package channel used ...[truncated 1592 chars]- Remediation
View remediation
