T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Homebrew Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4–11
Vulnerability Type: Unpinned dependency from a third-party Homebrew tap
Risk Level: MediumVulnerable Code Snippet
yaml metadata: {"clawdbot":{"emoji":"🔌","os":["darwin","linux","windows"],"requires":{"bins":["mcporter"]},"install":[{"id":"brew","kind":"brew","formula":"pdxfinder/tap/mcporter","bins":["mcporter"],"label":"Install mcporter (brew)"}]}} # mcporter Use `mcporter` to manage MCP (Model Context Protocol) servers and tools. ## Requirements - `mcporter` CLI installed (via Homebrew: `brew install pdxfinder/tap/mcporter`)Technical Analysis
The skill directs users or agents to install
mcporterfrom the custom third-party Homebrew tappdxfinder/tap. The dependency is not pinned to an audited version or repository commit, and the instructions provide no checksum or signature verification.Because the formula is mutable, the code executed during installation can change after this skill has been reviewed. A compromise of the tap repository, its maintainer account, or its upstream release-distribution process could cause Homebrew to retrieve and execute attacker-controlled installation logic. This is a supply-chain risk; the audit did not find evidence that the current package is malicious.
Attack Path
- An attacker compromises the third-party Homebrew tap, a maintainer account, or the referenced upstream artifact-distribution channel.
- The attacker modifies the formula or release artifact to include malicious installation-time or runtime code.
- A user or automated agent follows the skill metadata or documented command:
bash brew install pdxfinder/tap/mcporter - Homebrew resolves the mutable third-party formula and downloads the compromised content.
- The malicious code executes with the privileges of the account performing the installation.
- If the compromised CLI is later used for authentication or MCP calls, it may also access ...[truncated 716 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed release version or an immutable tap repository commit rather than relying on the mutable latest formula.
- Publish and verify cryptographic checksums or signatures for downloaded release artifacts.
- Prefer an official, trusted distribution channel when one is available.
- Document the expected package version, source repository, checksum, and verification procedure directly in the skill.
- Avoid unattended installation or automatic execution of third-party formulas without explicit user approval.
- Review the formula and its upstream artifacts before updating the pinned version.
- Run the CLI with least privilege and restrict access to unrelated credentials and sensitive files.
