Back to skill

Security audit

duely

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent command-line task tracker, but users should be aware it installs an unpinned third-party Homebrew package.

Install only if you trust the halbotley Homebrew tap or can verify the duely package yourself. Use the remove command carefully, since the skill does not say whether deleted task data can be recovered.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Executable Dependency Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-15 and 30-32
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
install:
  - id: brew
    kind: brew
    formula: halbotley/tap/duely
    bins: ["duely"]
    label: "Install duely (brew)"
bash
brew tap halbotley/tap
brew install duely

Technical Analysis

The Skill directs users or agents to install and execute the duely binary from the third-party Homebrew tap halbotley/tap. The dependency is not pinned to an immutable release, commit, package digest, or cryptographic checksum.

Consequently, the formula and its referenced installation artifacts can change after the Skill has been reviewed. The project contains no source code, lockfile, checksum, signature requirement, or other integrity metadata through which the installed implementation can be independently verified. This creates a supply-chain trust boundary between the audited Skill and an externally controlled package source.

There is no evidence in the reviewed file that the current package is malicious. The vulnerability is the unsafe, mutable dependency acquisition mechanism and the resulting inability to guarantee that future installations match the reviewed behavior.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer account, or an artifact location referenced by its formula.
  2. The attacker modifies the formula or distributed package so that installation logic or the resulting duely executable contains malicious code.
  3. A user or agent follows SKILL.md and runs brew tap halbotley/tap followed by brew install duely, or allows the declared installation metadata to trigger the equivalent installation.
  4. Homebrew retrieves the mutable formula and executes its installation process.
  5. The malicious package executes with the privileges of the account running Homebrew. ...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable third-party tap dependency with a reviewed official or first-party distribution source where one is available.
  2. Pin the dependency to an immutable release version or commit rather than installing the current tap head implicitly.
  3. Record and verify a SHA-256 checksum or trusted cryptographic signature for the downloaded artifact before installation.
  4. Link to auditable source code and document the exact source revision used to build the distributed binary.
  5. Use reproducible builds or a controlled internal package mirror so reviewers can verify that the installed binary corresponds to the audited source.
  6. Configure automated dependency monitoring and require renewed security review whenever the pinned version, formula, checksum, or upstream source changes.
  7. Avoid unattended installation from the tap until integrity verification and version pinning are implemented.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents a destructive command, duely remove old-task, without warning that it may permanently delete tracked task definitions or associated history. In an agent-assisted context, a model or user could invoke removal during cleanup or task management without understanding the data-loss consequence, leading to accidental destruction of local records.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description says to use the skill for 'scheduling, checking, and logging periodic tasks like backups, reviews, or any repeating chore,' which is quite broad and lacks explicit constraints or exclusion examples. This could overlap with many everyday task-management requests, making activation boundaries unclear.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.