T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Security-Sensitive Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Mediumyaml metadata: {"clawdbot":{"emoji":"🥡","requires":{"bins":["ordercli"]},"install":[{"id":"go","kind":"go","module":"github.com/steipete/ordercli/cmd/ordercli@latest","bins":["ordercli"],"label":"Install ordercli (go)"}]}}Technical Analysis
The installation metadata retrieves
orderclifrom a third-party Go module using the mutable@latestversion selector. Consequently, installation can resolve to code that differs from the version reviewed during this audit.This CLI is security-sensitive because the documented workflow grants it access to Foodora credentials or an authenticated browser session. It can also inspect order history and place purchases. Although no malicious behavior was found in the audited
SKILL.md, the dependency is not included in the project and its future contents cannot be established from this artifact.Attack Path
- An attacker compromises the upstream repository, maintainer account, release process, or another relevant supply-chain component.
- The attacker publishes a malicious version that becomes the version resolved by
@latest. - A user or agent installs the Skill dependency according to the metadata.
- The malicious
ordercliexecutable runs when the documented Foodora commands are invoked. - During login or session import, the executable may capture Foodora credentials or authenticated session material.
- It may then abuse account access, alter ordering operations, or execute arbitrary actions with the privileges of the user running the CLI.
Impact Assessment
Successful exploitation could execute attacker-controlled code under the installing user's operating-system privileges. Within the declared workflow, it could expose Foodora passwords or authenticated session data, disclose account and order information, and perfor ...[truncated 156 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a specific, reviewed release version or immutable commit. - Establish a controlled dependency-update process that includes source review and security testing before changing the pinned version.
- Verify release provenance and integrity where supported, and retain expected checksums or equivalent verification data.
- Prefer reproducible installation mechanisms that fail closed when the expected artifact cannot be verified.
- Run the CLI with the minimum necessary operating-system and account privileges.
- Avoid exposing credentials through command-line arguments; continue using standard input or a narrowly scoped authentication mechanism.
- Revoke Foodora sessions and investigate account activity if dependency compromise is suspected.
- Replace
