T08 · Insecure Dependencies
- Location
SKILL.md:135- Finding
Unpinned IDE Extension Dependency Can Enable Supply-Chain Impersonation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 135 and 223
Vulnerability Type: Unverified and unpinned third-party dependency
Risk Level: MediumVulnerable Instruction Snippet
The following is a faithful English translation of the relevant source instructions:
markdown Search for and install the "Node Protocol" extension from the VSCode or Cursor extension marketplace. | Node Protocol extension | IDE extension | Required | Search and install from the IDE extension marketplace |Technical Analysis
The skill requires an IDE extension but identifies it only by a generic display name. It does not provide an exact marketplace identifier, verified publisher, trusted listing URL, approved version, package checksum, signature-verification procedure, or other provenance information.
Marketplace searches can return similarly named packages. An attacker could therefore publish a counterfeit or typosquatted extension that appears to satisfy the documented dependency. This risk is material because the extension is expected to access the IDE workspace and maintain communication with a gateway. The skill documentation also describes remote file reading, writing, editing, deletion, language-service operations, and Git access.
This is a supply-chain weakness rather than evidence that the referenced extension is itself malicious.
Attack Path
- An attacker publishes a malicious IDE extension with a name, icon, description, and keywords resembling the unspecified "Node Protocol" extension.
- A user follows the skill documentation and searches the extension marketplace by display name.
- The user selects and installs the counterfeit extension because no authoritative publisher or extension identifier is provided for comparison.
- The extension requests or receives workspace and network capabilities appropriate for an IDE integration.
- The malicious extension reads source files or credenti ...[truncated 1066 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace name-based search instructions with a direct HTTPS link to the authoritative marketplace listing.
- Document the exact extension identifier in
publisher.extension-nameform and the verified publisher identity. - Pin an approved extension version instead of implicitly accepting the latest available release.
- For controlled deployments, provide a cryptographic checksum for the approved extension package and verify it before installation.
- Distribute the extension through an organization-managed allowlist or private registry where feasible.
- Document the permissions, network destinations, and gateway endpoints legitimately required by the extension.
- Disable unrestricted automatic updates or require review and integrity validation before deploying updates.
- Add an installation verification step that confirms the identifier, publisher, version, signature, and package source before the extension is enabled.
- Apply least-privilege gateway command allowlists and restrict extension access to only the intended workspaces.
