T08 · Insecure Dependencies
- Location
SKILL.md:290- Finding
Unpinned Third-Party CLI Is Granted Persistent Agent Execution Approval
- Content
View full analysis
**Third-party tap**: `mycelium-io/tap` is not an official Homebrew tap. Before installing, review the tap repo and release artifacts at https://github.com/mycelium-io/homebrew-tap to confirm you trust the source. ```bash brew install mycelium-io/tap/mycelium ``` Source: https://github.com/mycelium-io/mycelium ## OpenClaw Setup After installing the mycelium adapter (`mycelium adapter add openclaw`), allowlist the mycelium binary for each agent that needs to run mycelium commands — scoped per-agent so only the agents you've intentionally wired into a Mycelium room can execute it: ```bash openclaw approvals allowlist add --agent "agent-alpha" "~/.local/bin/mycelium" openclaw approvals allowlist add --agent "agent-beta" "~/.local/bin/mycelium" ``` ``` ### Technical Analysis The installation process retrieves the Mycelium executable through a third-party, explicitly non-official Homebrew tap. The instructions do not pin an immutable release, commit, checksum, or cryptographic signature. Consequently, the actual executable installed later may differ from the artifact an operator previously reviewed. The subsequent OpenClaw configuration persistently allowlists the installed executable for selected agents. This suppresses repeated execution approval prompts and increases the impact of a compromised release, tap formula, upstream repository, or update channel. The network download and CLI execution are relevant to the Skill's declared coordination functionality. However, trusting a mutable third-party distribution source and granting the resulting binary persistent approval exceeds the minimum assurance necessary to install a fixed, reviewed release. The pre-scan characterization of a download from a personal pastebin site was not substantiated by the ...[truncated 1289 chars]- Remediation
View remediation
