T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-17
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code
yaml install: - kind: brew formula: runapi-ai/tap/runapi bins: - runapiThe related production-integration instructions at lines 97-104 also direct the agent to obtain current package installation information from a mutable external SDK reference:
markdown Use this route only for application or production-code integration. Open the current RunAPI SDK reference below, select the package for the target language and `OpenAI Transcription`, and confirm its install command, client methods, request types, response types, and error classes before coding. Build the request from the same discovered product contract and apply the same deliverable verification and stop rules. Do not invoke `runapi` as a subprocess from production code. ## References - Model overview, pricing, and rate limits: https://runapi.ai/models/openai-transcription.md - Provider overview: https://runapi.ai/providers/openai.md - Full model catalog: https://runapi.ai/models.md - SDK integration: https://github.com/runapi-ai/openai-transcription-sdkTechnical Analysis
The skill specifies a third-party Homebrew tap and formula without pinning an audited version, immutable commit, checksum, or cryptographic signature. The production integration route similarly delegates package selection and installation details to mutable remote documentation.
This creates a supply-chain trust gap: the effective software installed when the skill is used may differ from the dependency state that existed during this audit. Although the audit found no evidence that the currently referenced project is malicious, compromise of the tap, formula repository, SDK repository, publishing account, or referenced documentation could cause an agent to install altered code.
Attack Path
...[truncated 1077 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a reviewed, explicit version rather than installing the mutable latest formula.
- Pin third-party source repositories to immutable commit hashes or signed release tags.
- Verify downloaded artifacts using documented cryptographic checksums and release signatures before installation.
- Record exact SDK package names and approved versions instead of delegating package selection entirely to mutable remote documentation.
- Use lockfiles with integrity metadata for application integrations and enforce them in CI.
- Restrict dependency installation and execution to a sandbox or minimally privileged account without unrelated credentials.
- Establish a controlled upgrade process in which new dependency versions are reviewed and verified before the pins are updated.
