Skip to content

Critical: T-EVADE-005 -> External Dependency Staging (Dependency Spoofing)#3

Open
Sumi0 wants to merge 2 commits intoopenclaw:mainfrom
Sumi0:main
Open

Critical: T-EVADE-005 -> External Dependency Staging (Dependency Spoofing)#3
Sumi0 wants to merge 2 commits intoopenclaw:mainfrom
Sumi0:main

Conversation

@Sumi0
Copy link
Copy Markdown

@Sumi0 Sumi0 commented Feb 9, 2026

"Defense Evasion via Socially Engineered External Prerequisites"
[Sub-type to T-EVADE-004]
While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite.

Sumi0 added 2 commits February 9, 2026 17:50
"Defense Evasion via Socially Engineered External Prerequisites"
[Sub-type to T-EVADE-004]
While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite.
Copy link
Copy Markdown

@kwasham kwasham left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PASS: Reviewed the new threat model write-up for T-EVADE-005. The docs-only changes don't introduce code, secrets, or auth/RLS surface area, and they responsibly document the attack chain and mitigations. No status checks are configured for this repo (statusCheckRollup is empty), so there was no CI to re-run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants