T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Executable Dependency from a Third-Party Homebrew Tap
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 6
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"🎮","requires":{"bins":["gog"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/gogcli","bins":["gog"],"label":"Install gog (brew)"}]}}Technical Analysis
The skill directs the environment to install
gogclifrom the third-party Homebrew tapsteipete/tap. The dependency is not pinned to an immutable version, formula revision, source commit, or cryptographic checksum. Consequently, the code ultimately installed and executed can change after this skill has been reviewed.The dependency source is external to the audited project, which contains only
SKILL.mdand_meta.json. Its implementation and installation behavior therefore cannot be verified from this artifact. If the tap, formula, upstream release infrastructure, or maintainer account were compromised, a modified package or installation procedure could be delivered under the expected package name.This is especially security-sensitive because the installed CLI is instructed to obtain OAuth authorization for Gmail, Calendar, Drive, Contacts, Sheets, and Docs. Although those permissions are consistent with the stated purpose of the skill, a compromised executable could misuse the resulting authorization.
Attack Path
- An attacker compromises or gains unauthorized publication access to the third-party Homebrew tap, its formula source, or the referenced upstream release channel.
- The attacker modifies the formula or package artifact while preserving the expected
steipete/tap/gogcliidentity. - A user installs the skill dependency, causing Homebrew to resolve the current mutable formula and execute its installation logic.
- The user follows the documented OAuth setup and grants the installed
gogexecutable access to one or mo ...[truncated 1049 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed, immutable release or formula revision rather than resolving the latest mutable tap content.
- Verify package artifacts with published cryptographic checksums or signatures before installation.
- Reference and document the authoritative upstream source and the exact reviewed version.
- Prefer a trusted distribution channel with reproducible builds and provenance attestations where available.
- Review the external formula and upstream source before approving installation or version upgrades.
- Grant only the Google Workspace OAuth services and scopes required for the immediate task.
- Store OAuth credentials using an operating-system-backed secure credential store and restrict their filesystem permissions.
- Revoke and rotate OAuth tokens promptly if dependency integrity is questioned.
- Treat dependency upgrades as security-sensitive changes and repeat source and integrity review before deployment.
