T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type: Supply-chain risk caused by mutable, unpinned third-party installation sources
Risk Level: MediumVulnerable Code Snippet
yaml metadata: {"clawdbot":{"emoji":"📱","requires":{"bins":["wacli"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/wacli","bins":["wacli"],"label":"Install wacli (brew)"},{"id":"go","kind":"go","module":"github.com/steipete/wacli/cmd/wacli@latest","bins":["wacli"],"label":"Install wacli (go)"}]}}Technical Analysis
The Skill defines two installation methods for the
wacliexecutable:- A third-party Homebrew tap,
steipete/tap/wacli - A Go module using the mutable version selector
@latest
Neither method pins the dependency to an immutable, reviewed release or commit. The
@latestselector resolves dynamically at installation time, so the installed source can change after this Skill has been audited. The Homebrew formula is likewise referenced without an explicit version, artifact digest, or signature-verification requirement.This creates a supply-chain trust gap: compromise of the upstream repository, package publication process, maintainer account, or Homebrew tap could result in installation of code that was not represented by the reviewed Skill content. The project contains no evidence that such a compromise has occurred; the finding concerns the unsafe dependency resolution mechanism.
Attack Path
- An attacker compromises an upstream maintainer account, source repository, release process, or the referenced Homebrew tap.
- The attacker publishes a malicious release or modifies the formula or source selected by the unpinned installation reference.
- A user or Agent installs
wacliusing the Skill's Go@latestoption or third-party Homebrew formula. - The package installation process or resulting executable runs attacker-controlled code with the privileges of ...[truncated 1135 chars]
- A third-party Homebrew tap,
- Remediation
View remediation
Remediation Suggestions
-
Replace the Go
@latestreference with a specific, reviewed semantic version:text github.com/steipete/wacli/cmd/wacli@vX.Y.ZFor stronger immutability, pin and document the reviewed upstream commit corresponding to that release.
-
Pin the Homebrew installation to a reviewed release rather than relying on the tap's current formula state. If the installation framework cannot enforce a specific formula revision, prefer a verifiable release artifact.
-
Record and verify cryptographic checksums for downloaded release artifacts before execution. Use upstream signature verification where trusted signing metadata is available.
-
Configure dependency automation to propose explicit version updates for review rather than resolving the newest upstream version during installation.
-
Review installation scripts and dependency changes whenever the pinned version is updated, particularly because the installed tool can access authentication state and private message history.
-
Run installation and use under a least-privileged account, and restrict access to
~/.wacliso that only the intended user can read its contents.
-
