Back to skill

Security audit

Sonoscli

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Sonos control helper, with the main caution that it installs an unpinned third-party Go CLI.

Before installing, consider that the CLI is fetched from a third-party Go module using @latest. Install only if you trust that upstream project, and avoid exposing unrelated secrets in the environment when running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Remote Go Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Mutable third-party dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🔊","requires":{"bins":["sonos"]},"install":[{"id":"go","kind":"go","module":"github.com/steipete/sonoscli/cmd/sonos@latest","bins":["sonos"],"label":"Install sonoscli (go)"}]}}

Technical Analysis

The installation metadata directs the host to retrieve, compile, and install the third-party Go module github.com/steipete/sonoscli/cmd/sonos@latest. The @latest selector is mutable and may resolve to different source code over time. Consequently, the executable installed after this audit may not be the same version that was previously reviewed.

This creates a supply-chain risk because the effective code is hosted outside the project and is not pinned to a reviewed release or commit. If the upstream repository, maintainer account, release process, or transitive dependency chain is compromised, attacker-controlled code could be incorporated into the installed executable.

Attack Path

  1. An attacker compromises the upstream project, a maintainer account, its release process, or a relevant transitive dependency.
  2. The attacker publishes a malicious version that becomes the version resolved by @latest.
  3. A user installs the Skill or triggers its dependency installation.
  4. The Go toolchain retrieves and compiles the changed upstream source.
  5. The resulting attacker-controlled sonos binary is installed and subsequently executed as the installing user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing installation or running the CLI. This may expose files, environment variables, and credentials accessible to that user, including optional Spotify credentials if they are present in the process environment. It could also enable unauthorize ...[truncated 329 chars]

Remediation
View remediation

Remediation Suggestions

Replace @latest with a reviewed, explicit semantic version or immutable commit reference. Maintain a controlled dependency-update process that includes source review, release-diff inspection, and testing before changing the pinned version.

Verify downloaded modules using the Go checksum database or an approved internal checksum mechanism. Where feasible, record and validate expected artifact hashes, review transitive dependencies, and build the CLI in an isolated environment with minimal filesystem, credential, and network access. Avoid exposing unrelated secrets to the installation or execution process.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.