Back to skill

Security audit

summarize

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent summarization wrapper, but users should understand that selected content may be processed remotely and that its CLI is installed from a third-party Homebrew tap.

Install only if you are comfortable using the steipete Homebrew tap and sending chosen summarization inputs through SkillBoss API Hub and possibly downstream model or scraping services. Do not summarize confidential local files, restricted URLs, private transcripts, or regulated data unless your organization permits that remote processing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: Unverified third-party dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"],"env":["SKILLBOSS_API_KEY"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}

Technical Analysis

The skill directs the host to install the summarize executable from the third-party Homebrew tap steipete/tap. The dependency is not pinned to an immutable version or commit, and the skill supplies no expected checksum or signature for artifact verification.

Consequently, the executable installed at deployment time may differ from the artifact originally reviewed. The project contains only SKILL.md; it does not include the executable's source code or another mechanism through which its behavior can be independently verified.

This is a supply-chain trust weakness rather than evidence that the current package is malicious. Exploitation would require compromise or malicious modification of the tap, formula, upstream release, or distribution account.

Attack Path

  1. An attacker compromises or gains publishing access to the third-party Homebrew tap, its upstream release location, or a related distribution account.
  2. The attacker modifies the formula or referenced artifact to install a malicious summarize executable.
  3. A user installs or upgrades the dependency through the skill's declared installation mechanism.
  4. Homebrew executes the affected installation logic or places the modified executable on the user's system.
  5. When the skill invokes summarize, the attacker-controlled executable runs with the privileges of the installing or invoking user.
  6. The executable can access inputs provided to it, potentially including local documents, URLs, configuration data, and the `SKILLBOSS_API_ ...[truncated 611 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an immutable release version and, where supported, an immutable source commit.
  2. Verify downloaded artifacts using a documented SHA-256 checksum and a cryptographic signature from a trusted maintainer.
  3. Prefer an official, reviewed distribution channel with reproducible release artifacts over a mutable third-party tap.
  4. Publish or vendor the source corresponding to the installed executable so its behavior can be audited.
  5. Run the CLI with least privilege and expose SKILLBOSS_API_KEY only for the duration of the required command.
  6. Restrict the executable's filesystem and network access through sandboxing where practical.
  7. Establish dependency monitoring and require security review before accepting formula or upstream release changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states that content is routed through SkillBoss API Hub and may use remote scraping/transcript fallback services, but it does not clearly warn users that submitted URLs, local files, and extracted content may be transmitted to third-party infrastructure. This creates a real data exposure and informed-consent issue, especially when users may summarize sensitive local documents or restricted URLs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill directs use of an external API endpoint for summarization and notes automatic routing across multiple model providers. In the context of summarizing URLs and local files, this means user-supplied content may leave the local environment and be processed remotely, which is security-relevant and potentially sensitive if not clearly constrained or disclosed.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
## Model + keys

Set the API key for SkillBoss API Hub:
- `SKILLBOSS_API_KEY` — unified key for all providers, routes via `https://api.skillbossai.com/v1/pilot`

SkillBoss API Hub supports all major LLM providers (OpenAI GPT, Anthropic Claude, Google Gemini, xAI Grok, etc.) and automatically selects the best model. No provider-specific keys needed.

Static analysis

No suspicious patterns detected.