T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party Homebrew Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 7
Vulnerability Type: Third-party dependency supply-chain risk
Risk Level: MediumAffected code:
yaml metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["notesmd-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/notesmd-cli","bins":["notesmd-cli"],"label":"Install notesmd-cli (brew)"}]}}Technical Analysis
The Skill instructs the environment to install
notesmd-clifrom the third-party Homebrew tapyakitrak/yakitrak. The dependency is not pinned to an immutable source revision, and the package contains no checksum, signature requirement, or vendored source through which the installed implementation can be independently reviewed.Consequently, the code installed when the formula is resolved may differ from the implementation originally reviewed. If the tap, formula, upstream artifact, or maintainer account is compromised, an attacker could substitute malicious installation logic or a malicious
notesmd-cliexecutable.This finding does not establish that the current dependency is malicious. It identifies an unsafe, mutable trust boundary that can permit supply-chain compromise.
Attack Path
- An attacker compromises the third-party Homebrew tap, its maintainer account, the formula source, or an artifact downloaded by the formula.
- The attacker modifies the formula or referenced artifact to install and execute a malicious version of
notesmd-cli. - A user installs the dependency through the Skill's declared Homebrew installation mechanism.
- Homebrew retrieves the attacker-controlled mutable content and runs the associated installation steps with the invoking user's privileges.
- When the Skill invokes
notesmd-cli, the substituted executable can access the user's Obsidian configuration and vault data in the process's permission scope. - The malicious executable could read, alter, delete, or ex ...[truncated 851 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer an audited dependency distributed through an official or otherwise strongly governed package source.
- Pin the dependency to an immutable release and source commit rather than relying only on a mutable formula name.
- Verify downloaded artifacts with cryptographic checksums or signatures whose expected values are maintained in a trusted location.
- Review and record the Homebrew formula, its installation hooks, and all upstream artifacts before approving installation.
- Use Homebrew lockfiles, an internal package mirror, or a vetted vendored binary where operationally appropriate.
- Run the CLI under a least-privileged account or sandbox with access restricted to the intended Obsidian vault.
- Require explicit confirmation before destructive operations such as note deletion or bulk link rewrites.
- Monitor dependency ownership and release changes, and repeat the security review whenever the pinned version is updated.
