T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party CLI Installation from a Mutable Upstream Revision
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5–13
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"✅","os":["darwin"],"requires":{"bins":["things"]},"install":[{"id":"go","kind":"go","module":"github.com/ossianhempel/things3-cli/cmd/things@latest","bins":["things"],"label":"Install things3-cli (go)"}]}}shell GOBIN=/opt/homebrew/bin go install github.com/ossianhempel/things3-cli/cmd/things@latestTechnical Analysis
The Skill installs
things3-cliusing the mutable Go version selector@latest. This does not bind installation to the specific dependency revision that was reviewed when the Skill was published. Consequently, the effective code installed and executed on a user's machine can change without any corresponding modification to this Skill package.If the upstream repository, maintainer account, release process, or relevant dependency chain is compromised, a malicious future version could be selected automatically. Because Go installation compiles dependency code into a local executable, the resulting
thingsbinary could perform arbitrary actions under the invoking user's permissions whenever it is run.The Skill also conditionally recommends granting Full Disk Access to the calling application when database reads fail. That recommendation is legitimate for the documented Things database operation, but it can amplify the consequences of a compromised dependency by making additional user files accessible to the process.
Attack Path
- An attacker compromises the upstream repository, maintainer credentials, release workflow, or dependency chain for
github.com/ossianhempel/things3-cli. - The attacker publishes a malicious revision that is resolved by the mutable
@latestselector. - A user or agent follows the Skill installation metadata or setup command.
- Go downloads, compiles, an ...[truncated 1197 chars]
- An attacker compromises the upstream repository, maintainer credentials, release workflow, or dependency chain for
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a specific, audited semantic version or immutable commit revision in both the installation metadata and documented setup command. - Record the approved upstream revision and review its source code and transitive dependency versions before publication.
- Use reproducible dependency controls, such as a locked Go module dependency graph and verified module checksums.
- Establish an explicit upgrade process in which dependency updates are reviewed, tested, and released as new Skill versions rather than selected dynamically during installation.
- Document the security implications of Full Disk Access and instruct users to grant it only to the minimum necessary application after verifying the installed CLI.
- Advise users to store
THINGS_AUTH_TOKENin a suitably protected credential mechanism and avoid exposing it in command history or process arguments.
- Replace
