Skip to content

Critical: T-EVADE-005 -> External Dependency Staging (Dependency Spoofing)#3

Open
Sumi0 wants to merge 2 commits intoopenclaw:mainfrom
Sumi0:main
Open

Critical: T-EVADE-005 -> External Dependency Staging (Dependency Spoofing)#3
Sumi0 wants to merge 2 commits intoopenclaw:mainfrom
Sumi0:main

Conversation

@Sumi0
Copy link

@Sumi0 Sumi0 commented Feb 9, 2026

"Defense Evasion via Socially Engineered External Prerequisites"
[Sub-type to T-EVADE-004]
While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite.

Sumi0 added 2 commits February 9, 2026 17:50
"Defense Evasion via Socially Engineered External Prerequisites"
[Sub-type to T-EVADE-004]
While T-EVADE-004 covers a skill automatically fetching code at runtime, this T-EVADE-005 is a social engineering hybrid. It doesn't fetch the code invisibly in the background; it tricks the user into manually downloading and executing the payload by masquerading as a prerequisite.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant