T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Homebrew Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Supply-chain exposure through an unpinned third-party Homebrew tap
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["obsidian-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/obsidian-cli","bins":["obsidian-cli"],"label":"Install obsidian-cli (brew)"}]}}Technical Analysis
The skill directs the environment to install
obsidian-clifrom the third-party Homebrew tapyakitrak/yakitrakwithout pinning the dependency to a reviewed version, formula revision, commit, or artifact checksum. Consequently, the code installed at a later date can differ from the code that existed when this skill was audited.Homebrew formulas can download and install external artifacts and execute formula-defined build or installation operations. If the tap repository, its maintainer account, its release infrastructure, or an upstream artifact is compromised, an attacker could replace a future version or modify the formula. A subsequent installation initiated through this skill would then trust and execute the modified supply-chain content.
The available files contain no evidence that this tap or package is currently malicious. The security issue is the lack of reproducibility and integrity controls around an externally mutable installation source.
Attack Path
- An attacker compromises the third-party tap repository, a maintainer account, the upstream release process, or an artifact hosting location used by the formula.
- The attacker publishes a modified formula or replaces an artifact referenced by a formula version that is not protected by an effective integrity check.
- A user loads the skill on a system where
obsidian-cliis absent and follows or authorizes the declared Homebrew installation action. - Homebrew retrieves the then-current formula and associated ...[truncated 1002 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed release and, where supported, a fixed tap commit or immutable artifact.
- Verify downloaded artifacts with a cryptographic checksum sourced from a trusted and independently authenticated channel.
- Prefer an official package source maintained by the upstream project over a third-party tap when one is available.
- Document the exact expected
obsidian-cliversion and validate it after installation before allowing the agent to invoke it. - Review the Homebrew formula, upstream source, release provenance, and transitive dependencies before approving installation.
- Use signed releases or provenance attestations where the upstream project provides them.
- Perform installation and execution as an unprivileged user in a restricted environment, granting access only to the intended Obsidian vault.
- Avoid automatic dependency installation. Require explicit user approval that identifies the external source and selected version.
- Periodically re-audit the pinned release before deliberately updating it rather than automatically tracking the latest formula.
