Back to skill

Security audit

F1 CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Formula 1 data helper that installs and uses a third-party CLI, with manageable install and activation-scope caveats.

Install only if you are comfortable trusting the third-party f1 CLI source. Prefer a pinned release or reviewed Homebrew formula revision when possible, and expect the skill to make network requests to OpenF1 for public Formula 1 data, sometimes even for broad F1-related prompts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party CLI Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22-28
Vulnerability Type: Unpinned and mutable third-party dependency installation
Risk Level: Medium

Vulnerable Code:

bash
brew tap barronlroth/tap
brew install f1-cli

Or from source:

bash
go install github.com/barronlroth/f1-cli/cmd/f1@latest

Technical Analysis

The installation instructions retrieve the f1 CLI from a third-party Homebrew tap or directly from a Go repository using the mutable @latest reference. Neither method pins the dependency to an immutable, previously reviewed version, and no checksum or cryptographic signature verification is required.

Consequently, the code installed by users can change after this skill has been audited. If the upstream repository, maintainer account, Homebrew tap, release process, or another relevant distribution component is compromised, an attacker could publish a modified package that is installed through the documented commands. The risk is especially clear for @latest, which explicitly resolves to whatever version upstream currently exposes.

This finding does not establish that the current upstream project is malicious. It identifies a reproducibility and supply-chain trust weakness in the documented installation procedure.

Attack Path

  1. An attacker compromises the upstream repository, third-party Homebrew tap, maintainer credentials, or package publication process.
  2. The attacker publishes a malicious release or modifies the package metadata referenced by the installation commands.
  3. A user or agent follows SKILL.md and installs the dependency through Homebrew or go install ...@latest.
  4. Because no immutable version or artifact integrity check is specified, the malicious version is accepted and installed.
  5. The installed f1 executable is subsequently invoked for Formula 1 queries.
  6. Attacker-controlled code executes with the permissions and environ ...[truncated 665 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the Go installation to a specific reviewed release rather than @latest, for example:
    bash
    go install github.com/barronlroth/f1-cli/cmd/f1@vX.Y.Z
    
  2. Pin the Homebrew formula or document an approved formula revision where operationally feasible.
  3. Prefer official, versioned release artifacts from a trusted source.
  4. Publish and verify SHA-256 checksums or cryptographic signatures before installation.
  5. Record the expected repository owner, version, artifact digest, and binary provenance in SKILL.md.
  6. Review dependency changes before updating the pinned version.
  7. Run the CLI with least privilege and avoid exposing unrelated secrets or sensitive environment variables to its process.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is unusually broad, covering not just explicit requests to use the F1 CLI but also casual mentions of F1, driver names, and vague sports-stat questions. In an agent setting, this can cause the skill to activate for ordinary conversation or weak matches, leading to unnecessary tool use, incorrect routing, and untrusted external data retrieval when a normal text answer would be safer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.