[PR #3] Critical: T-EVADE-005 -> External Dependency Staging (Dependency Spoofing) #5

Open
opened 2026-02-15 18:15:53 -05:00 by yindo · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/openclaw/trust/pull/3
Author: @Sumi0
Created: 2/9/2026
Status: 🔄 Open

Base: mainHead: main


📝 Commits (2)

  • 1a79778 Critical: T-EVADE-005 -> Dependency Spoofing
  • 9be3eb6 Update threats.yaml with T-EVADE-005

📊 Changes

2 files changed (+486 additions, -0 deletions)

View changed files

Threat-Patttern/T-EVADE-005-external-dependency-staging.md (+466 -0)
📝 threats.yaml (+20 -0)

📄 Description

"Defense Evasion via Socially Engineered External Prerequisites"
[Sub-type to T-EVADE-004]
While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/openclaw/trust/pull/3 **Author:** [@Sumi0](https://github.com/Sumi0) **Created:** 2/9/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `main` --- ### 📝 Commits (2) - [`1a79778`](https://github.com/openclaw/trust/commit/1a797783663d092551c5a3608709306c3f780221) Critical: T-EVADE-005 -> Dependency Spoofing - [`9be3eb6`](https://github.com/openclaw/trust/commit/9be3eb648aa11648863cd2a487c5cfed5c10be82) Update threats.yaml with T-EVADE-005 ### 📊 Changes **2 files changed** (+486 additions, -0 deletions) <details> <summary>View changed files</summary> ➕ `Threat-Patttern/T-EVADE-005-external-dependency-staging.md` (+466 -0) 📝 `threats.yaml` (+20 -0) </details> ### 📄 Description "Defense Evasion via Socially Engineered External Prerequisites" [Sub-type to T-EVADE-004] While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
yindo added the pull-request label 2026-02-15 18:15:53 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: openclaw/trust#5