Back to skill

Security audit

Summarize

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent summarization helper, but users should treat submitted files and links as potentially sent to external services.

Install only if you trust the summarize CLI and its Homebrew tap. Avoid using it on confidential documents, private URLs, or sensitive transcripts unless you are comfortable sending that content to the selected model provider and optional extraction services such as Firecrawl or Apify.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14-19
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

json
{
  "id": "brew",
  "kind": "brew",
  "formula": "steipete/tap/summarize",
  "bins": ["summarize"],
  "label": "Install summarize (brew)"
}

Technical Analysis

The skill directs the framework to install the summarize executable from the third-party Homebrew tap steipete/tap. The dependency is not constrained to a reviewed version, immutable commit, or verified checksum. Consequently, the executable installed in the future may differ from the artifact that was originally reviewed.

This creates a supply-chain trust boundary outside the audited project. Although the reviewed SKILL.md contains no malicious payload, a compromise of the tap, formula, release infrastructure, or upstream artifact could cause the installation process to retrieve attacker-controlled executable code.

The risk is particularly relevant because the documented workflow supplies URLs and local file paths to the executable and relies on provider credentials such as OPENAI_API_KEY, ANTHROPIC_API_KEY, XAI_API_KEY, and GEMINI_API_KEY.

Attack Path

  1. An attacker compromises or gains control over the third-party tap, its formula, or an upstream release artifact referenced by the formula.
  2. The attacker modifies the package so that installation produces a malicious summarize executable.
  3. A user or agent installs the dependency using the skill's declared Homebrew installation metadata.
  4. The user or agent invokes summarize for a URL or local document.
  5. The altered executable runs with the invoking user's privileges.
  6. It may read supplied local files, inspect accessible environment variables, exfiltrate API credentials or document contents, and modify files writable by that user.

Impact Assessment

Successful exploitation permits code execution with the privileges of the user who i ...[truncated 549 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed release and immutable formula revision or commit.
  2. Verify downloaded artifacts against a documented SHA-256 checksum or cryptographic signature from a trusted official release channel.
  3. Confirm and document that the Homebrew tap and upstream repository are official and controlled by the expected publisher.
  4. Use a lockfile, vendored formula, or reproducible installation mechanism where supported.
  5. Run the executable with the minimum required privileges and avoid invoking package installation as an administrator.
  6. Provide only the credentials needed for the selected provider instead of exposing unrelated environment variables.
  7. Warn users that local file contents may be processed by an external executable and transmitted to configured model or extraction providers.
  8. Periodically review the pinned dependency and update it only after validating its source, integrity, and behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs use of external model providers and optional third-party services but does not warn that submitted URLs, local files, transcripts, or extracted content may be transmitted off-device. Users may provide confidential documents or private links expecting local handling, leading to unintended disclosure of sensitive data to OpenAI, Google, Anthropic, xAI, Firecrawl, or Apify.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases "what’s this link/video about?" and "summarize this URL/article" are broad enough to match many ordinary user requests, which can cause the skill to activate unexpectedly. Because this skill sends URLs, local files, or transcript content to external summarization services, accidental activation can expose sensitive content or route user data to third-party APIs without explicit intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.