T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Homebrew Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["obsidian-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/obsidian-cli","bins":["obsidian-cli"],"label":"Install obsidian-cli (brew)"}]}}Technical Analysis
The installation metadata directs users or an automated installer to obtain
obsidian-clifrom the third-party Homebrew tapyakitrak/yakitrak. The dependency is not pinned to an immutable release, commit, or verified artifact checksum. Consequently, the package installed in the future may differ from the package that existed when this Skill was reviewed.This creates a supply-chain trust boundary: control of the tap, its formula, its source archive, or the associated maintainer account could allow an attacker to distribute altered installation logic or a malicious replacement executable. Homebrew formula installation may execute build and installation procedures, while the resulting CLI operates with the invoking user's permissions.
No evidence in the audited files establishes that the referenced package is currently malicious. The risk arises from the mutable, unverified third-party dependency.
Attack Path
- An attacker compromises the third-party tap, its maintainer account, the formula repository, or an upstream artifact referenced by the formula.
- The attacker publishes a modified formula or package under the existing
obsidian-cliname. - A user or automated environment installs the dependency using the Skill's Homebrew installation metadata.
- Malicious logic executes during installation or is placed on the system as the expected
obsidian-cliexecutable. - When the Skill invokes the executable, it runs with the user's permissions and can access resources available to that user, includ ...[truncated 681 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer an official, trusted distribution channel for
obsidian-cliwhere one is available. - Pin the dependency to an immutable version or audited source commit rather than tracking a mutable third-party formula.
- Verify downloaded artifacts with a cryptographic checksum or signature tied to the approved release.
- Record the expected package version and integrity value in installation metadata or a reviewed lock mechanism.
- Review the Homebrew formula, its source URLs, and installation hooks before approving updates.
- Restrict automated dependency updates and require security review when the pinned version or checksum changes.
- Perform installation and execution as a non-privileged user with access limited to the intended vault whenever operationally feasible.
- Prefer an official, trusted distribution channel for
