T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Homebrew Dependency Used with Broad Privacy Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5-14
Vulnerability Type: Supply-chain exposure through an unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet
yaml metadata: {"clawdbot":{"emoji":"📨","os":["darwin"],"requires":{"bins":["imsg"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/imsg","bins":["imsg"],"label":"Install imsg (brew)"}]}} --- # imsg Use `imsg` to read and send Messages.app iMessage/SMS on macOS. Requirements - Messages.app signed in - Full Disk Access for your terminal - Automation permission to control Messages.app (for sending)Technical Analysis
The skill installs
imsgfrom the third-party Homebrew tapsteipete/tap/imsg. The dependency declaration does not specify an immutable version, source commit, cryptographic checksum, or signature. Consequently, the code installed in the future may differ from the version that was originally reviewed.This supply-chain exposure is amplified because the installed executable is intended to run from a terminal granted Full Disk Access and Messages.app automation permission. If the tap, formula, release infrastructure, or maintainer account were compromised, a modified package could execute with access to sensitive local data and control Messages.app.
The reviewed file does not establish that the current package is malicious. The vulnerability is the absence of integrity pinning and verification for a dependency that is expected to operate with high-impact privacy permissions.
Attack Path
- An attacker compromises the third-party Homebrew tap, its maintainer account, the referenced release artifact, or another component of its distribution infrastructure.
- The attacker modifies the formula or distributed artifact while retaining the expected package name.
- A user follows the skill installation metadata and installs or upgrades
steipete/tap/imsg. - Homebrew ...[truncated 1156 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specific, reviewed release rather than relying on a mutable formula reference.
- Record and verify a cryptographic digest for the exact release artifact before installation.
- Where supported, require signed releases and verify signatures against a documented, trusted maintainer key.
- Pin the Homebrew tap or formula source to an immutable reviewed commit and establish a controlled process for updating that pin.
- Document the authoritative source repository and release channel so users can detect lookalike or substituted packages.
- Avoid granting Full Disk Access to a general-purpose terminal. Prefer a narrowly scoped launcher or dedicated execution environment with only the permissions required for message access.
- Separate read and send capabilities where possible, granting Messages.app automation permission only when sending is required.
- Review dependency changes before upgrades and use lockfiles, internal mirrors, or approved artifact repositories where operationally feasible.
- Retain the existing requirement to confirm the recipient and message content before sending, and enforce that confirmation in the calling agent rather than relying solely on documentation.
