T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Executable Installed from a Third-Party Homebrew Tap
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:5
Vulnerability Type: Supply-chain risk caused by a mutable third-party dependency
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}Technical Analysis
The installation metadata directs users to install the
summarizeexecutable from the custom Homebrew tapsteipete/tap. The dependency is not pinned to an immutable release, commit, checksum, or cryptographically verified artifact.Because the executable and its source code are not included in the audited project, its installation and runtime behavior cannot be verified from this package. A future modification or compromise of the referenced tap, formula, release artifact, or upstream distribution infrastructure could change the effective code installed by this Skill without requiring any modification to
SKILL.md.This risk is particularly relevant because the documented executable processes local files and receives API credentials through environment variables. A malicious dependency could therefore attempt to access file contents and credentials available to the invoking process.
Attack Path
- An attacker compromises the third-party Homebrew tap, its maintainer account, the formula's upstream artifact source, or another relevant distribution component.
- The attacker modifies the formula or referenced package so that it installs a malicious version of the
summarizeexecutable. - A user or agent follows the installation metadata in
SKILL.mdand retrieves the mutable dependency. - Homebrew executes applicable installation logic and places the attacker-controlled executable on the user's system.
- When the Skill invokes
summarize, the malicious executable runs with the invoking user's pr ...[truncated 1100 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an immutable, reviewed release or commit rather than relying solely on a mutable formula name.
- Require verification of a published cryptographic checksum or signature before installing the executable.
- Prefer a trusted package repository with transparent provenance, reproducible builds, and release-signing controls.
- Record the exact reviewed version and its expected digest in the Skill metadata or installation documentation.
- Where practical, include auditable source code or a locked dependency manifest in the project.
- Run the executable with least privilege and restrict its access to unrelated files, credentials, and network destinations.
- Avoid exposing credentials for providers that are not required for the current operation.
- Document which local file contents, URLs, metadata, and credentials may be sent to external model or extraction services.
- Periodically review the tap formula, upstream artifacts, maintainer ownership, signatures, and checksums for unauthorized changes.
