T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unaudited Third-Party CLI Is Granted Access to the Poe API Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–18 and 27–31
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
yaml metadata: openclaw: emoji: "📊" homepage: https://github.com/rgstephens/poeusage-skill requires: bins: - poeusage env: - POE_API_KEY install: - kind: brew tap: rgstephens/tap formula: poeusage bins: - poeusageThe documented installation commands are:
bash brew tap rgstephens/tap brew install poeusageTechnical Analysis
The Skill delegates its entire runtime behavior to the external
poeusageexecutable, installed from the publisher-controlledrgstephens/tapHomebrew tap. The executable is granted access to the sensitivePOE_API_KEYenvironment variable and is expected to perform network requests.The audited project contains only
SKILL.md; it does not include the CLI implementation. It therefore provides no locally reviewable assurance regarding:- The network destinations receiving the credential.
- The scope and content of transmitted usage data.
- Credential logging or persistence behavior.
- The integrity of the installed executable.
- The behavior of future versions supplied through the tap.
The installation does not pin an immutable release, commit, artifact digest, or checksum. This does not prove that the dependency is malicious, but it creates a supply-chain trust boundary through which the effective executable can change after the Skill has been reviewed.
Network access and Poe authentication are necessary for the declared balance and usage-monitoring functionality. However, granting a mutable, unaudited third-party executable access to the credential without integrity controls exceeds what the Skill package itself can safely verify.
Attack Path
- An attacker compromises the t ...[truncated 1220 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a reviewed, immutable CLI release rather than an automatically changing formula.
- Verify the downloaded artifact using a cryptographic checksum or trusted signature.
- Publish or bundle the CLI source so its credential handling and network behavior can be audited with the Skill.
- Document the exact Poe API hostnames and network operations required by each command.
- Enforce an outbound destination allowlist where the execution environment supports it.
- Use reproducible builds and release provenance attestations to connect reviewed source to distributed binaries.
- Run the CLI with only the required credential and a minimal environment; do not expose unrelated secrets.
- Document upgrade review procedures so dependency changes are evaluated before deployment.
