superada-workflow-entity-mission-control-bootstrap
纯元数据技能,下载并执行外部仓库代码,供应链风险极高
install-auto.sh从github.com/h-mascot/enterprise-crew-skills下载执行,该脚本内容未包含在技能包中无法预先审查
SKILL.md:18 Why this conclusion was reached
2/4 dimensions flagged2 undeclared or violating capabilities were inferred.
1 lower-risk artifacts were extracted and still need context.
The report includes 4 attack-chain steps and 3 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
Entry · SKILL.md:18
Escalation · SKILL.md:18
Escalation · SKILL.md:18
Impact · SKILL.md:18
What drove the risk score up
install-auto.sh从github.com/h-mascot下载执行,未包含实际代码供审查
使用'Canonical source bundle'等措辞试图建立信任,但不可验证
SKILL.md描述的功能与实际下载执行的代码完全分离
Most important evidence
外部仓库代码执行
install-auto.sh从github.com/h-mascot/enterprise-crew-skills下载执行,该脚本内容未包含在技能包中无法预先审查
SKILL.md:18 远程脚本直接执行
bash skills/entity-mc/install-auto.sh直接执行下载的shell脚本,无沙箱或验证
SKILL.md:18 元数据技能伪装
该技能仅包含SKILL.md元数据,实际危险行为发生在外部仓库代码中,形成文档-行为分离
SKILL.md:1 cron条目写入
文档提到写入auto-pull和stall-check cron条目,具有持久化能力
SKILL.md:31 Declared capability vs actual capability
install-auto.sh会写入skills目录 bash install-auto.sh直接执行外部脚本 install-auto.sh可能读取敏感环境变量 — Suspicious artifacts and egress
https://superada.ai/workflows/entity-mission-control-bootstrap/ SKILL.md:11
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md Security positives
No explicit security positives were supplied.