Back to skill

Security audit

20206 02 10 Clawhub Summarize 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, coherent wrapper for a summarization CLI, but users should understand that files, URLs, and media may be processed by external services.

Install only if you are comfortable using the external summarize CLI and any configured model or fallback providers. Do not summarize confidential, regulated, or private files or URLs unless your organization approves those providers and their data handling.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

yaml
metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}

Technical Analysis

The skill instructs the environment to install the summarize executable from the third-party Homebrew tap steipete/tap. The dependency is not pinned to a reviewed version or immutable commit, and the skill provides no checksum or cryptographic signature for integrity verification.

Homebrew formulas and their referenced artifacts are mutable external dependencies. Consequently, the software ultimately installed can change after this skill package has been reviewed. The formula and executable source are not included in the audited project, so their installation behavior and runtime implementation cannot be verified from the supplied files.

This is a supply-chain weakness rather than evidence that the current external package is malicious.

Attack Path

  1. An attacker compromises the third-party tap, its maintainer account, or an upstream artifact referenced by the formula.
  2. The attacker modifies the formula or distributed package to include malicious installation logic or a malicious summarize executable.
  3. A user or agent processes the skill installation metadata and invokes Homebrew to install steipete/tap/summarize.
  4. Homebrew retrieves and executes the modified installation logic or installs the substituted executable.
  5. The malicious component runs during installation or when the skill later invokes summarize.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account running Homebrew or the installed executable. Potential effects include access to files ...[truncated 438 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer an official, trusted, and auditable distribution channel.
  • Pin the dependency to a specific reviewed release and, where supported, an immutable source commit.
  • Verify downloaded artifacts using a publisher-provided cryptographic signature or a trusted SHA-256 checksum.
  • Pin and review the Homebrew formula revision rather than relying on the mutable head of a third-party tap.
  • Vendor the reviewed formula or source when practical so the installed content can be audited with the skill.
  • Execute installation and subsequent CLI operations under a dedicated least-privileged account.
  • Restrict access to unrelated secrets and API credentials during installation.
  • Continuously monitor the pinned dependency for ownership changes, compromised releases, and newly disclosed vulnerabilities.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages summarizing URLs, local files, PDFs, images, audio, and YouTube content via external provider-backed CLI models, but it does not warn users that the referenced content may be transmitted to third-party APIs. This creates a real privacy and data-handling risk because users may supply sensitive local files or confidential URLs under the assumption processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation lists optional fallback services such as Firecrawl and Apify without clearly warning that these third parties may receive the target URLs, extracted content, or related metadata. This is dangerous because fallback behavior can expand the data-sharing surface beyond the primary model provider, reducing user awareness and informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.