T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned External CLI Dependency from Mutable Third-Party Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type: Supply-chain risk caused by mutable, externally distributed dependencies
Risk Level: MediumVulnerable Code Snippet
yaml metadata: {"clawdbot":{"emoji":"📝","requires":{"bins":["zm-md2wechat-conversion-tool"],"env":["WECHAT_APPID","WECHAT_SECRET"]},"install":[{"id":"brew","kind":"brew","formula":"geekjourneyx/tap/zm-md2wechat-conversion-tool","bins":["zm-md2wechat-conversion-tool"],"label":"Install zm-md2wechat-conversion-tool (brew)"},{"id":"go","kind":"go","module":"github.com/geekjourneyx/zm-md2wechat-conversion-tool-skill/cmd/zm-md2wechat-conversion-tool@latest","bins":["zm-md2wechat-conversion-tool"],"label":"Install zm-md2wechat-conversion-tool (go)"}]}}Technical Analysis
The skill offers two installation sources for its required executable:
- A custom Homebrew tap,
geekjourneyx/tap. - A Go module resolved using the mutable
@latestselector.
Neither installation declaration pins the executable to an immutable, audited release artifact or supplies a checksum or signature for verification. In particular,
@latestcan resolve to different code over time without any corresponding change to this reviewed skill package.The actual CLI implementation is not included in the audited artifact. Consequently, its behavior cannot be verified from the project files, even though the skill directs the executable to process local Markdown and image files, access WeChat credentials, call remote services, and upload content.
This is a supply-chain weakness rather than evidence that the current upstream package is malicious. Exploitation requires compromise or malicious modification of an upstream repository, release process, package source, or distribution account.
Attack Path
- An attacker compromises the Go repository, release pipeline, custom Homebrew tap, or associated maintainer account.
- The attacker publishes a modified version of `zm-md2 ...[truncated 1469 chars]
- A custom Homebrew tap,
- Remediation
View remediation
Remediation Suggestions
-
Replace the Go
@latestselector with a specific reviewed semantic version, for example:text github.com/geekjourneyx/zm-md2wechat-conversion-tool-skill/cmd/zm-md2wechat-conversion-tool@vX.Y.Z -
Pin Homebrew installation to a versioned formula backed by an immutable release artifact rather than relying solely on a mutable custom tap reference.
-
Publish cryptographic checksums for release artifacts and verify them during installation.
-
Sign releases using a verifiable mechanism such as Sigstore/cosign, signed tags, or another documented signing process.
-
Record the exact dependency version reviewed with each skill release and require explicit review before upgrading it.
-
Prefer reproducible builds and document how users can verify that a distributed binary corresponds to the reviewed source revision.
-
Run the CLI with least privilege:
- Provide WeChat credentials only for operations that require them.
- Restrict filesystem access to required input and output locations where sandboxing is available.
- Restrict outbound network access to documented service endpoints.
- Separate local conversion from credential-bearing publishing operations.
-
Include the executable source or a verifiable source revision in the audit scope so that its file, credential, network, and command-execution behavior can be independently reviewed.
-
