T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned CLI Installation from a Mutable Third-Party Homebrew Tap
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent, but it asks users to install an unpinned third-party CLI and give it an account token, with limited warning around account-changing coupon actions.
Review the upstream mcd-cn project and Homebrew tap before installing, use a minimally scoped token if available, avoid storing the token in a committed .env file, and treat auto-bind-coupons as an account-changing action rather than a read-only lookup.
SKILL.md:4Unpinned CLI Installation from a Mutable Third-Party Homebrew Tap
The skill advertises mcd-cn auto-bind-coupons as a common command but does not clearly warn that it performs an account-affecting action rather than a read-only lookup. In an agent context, this increases the chance of unintended coupon claiming or account state changes if a user or downstream automation assumes all listed commands are safe informational queries.
No suspicious patterns detected.