Back to skill

Security audit

skill-0327-02222

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent summarization skill, but users should understand it installs a third-party CLI and may send submitted content to external providers.

Install only if you trust the summarize Homebrew tap and the model or extraction providers you configure. Treat any URL, file, media, or YouTube content you submit as potentially sent to external services, and avoid sensitive or regulated material unless that use is approved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5
Vulnerability Type: Supply-chain risk caused by a mutable third-party dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}

Technical Analysis

The installation metadata directs users to install the summarize executable from the custom Homebrew tap steipete/tap. The dependency is not pinned to an immutable release, commit, checksum, or cryptographically verified artifact.

Because the executable and its source code are not included in the audited project, its installation and runtime behavior cannot be verified from this package. A future modification or compromise of the referenced tap, formula, release artifact, or upstream distribution infrastructure could change the effective code installed by this Skill without requiring any modification to SKILL.md.

This risk is particularly relevant because the documented executable processes local files and receives API credentials through environment variables. A malicious dependency could therefore attempt to access file contents and credentials available to the invoking process.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer account, the formula's upstream artifact source, or another relevant distribution component.
  2. The attacker modifies the formula or referenced package so that it installs a malicious version of the summarize executable.
  3. A user or agent follows the installation metadata in SKILL.md and retrieves the mutable dependency.
  4. Homebrew executes applicable installation logic and places the attacker-controlled executable on the user's system.
  5. When the Skill invokes summarize, the malicious executable runs with the invoking user's pr ...[truncated 1100 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an immutable, reviewed release or commit rather than relying solely on a mutable formula name.
  2. Require verification of a published cryptographic checksum or signature before installing the executable.
  3. Prefer a trusted package repository with transparent provenance, reproducible builds, and release-signing controls.
  4. Record the exact reviewed version and its expected digest in the Skill metadata or installation documentation.
  5. Where practical, include auditable source code or a locked dependency manifest in the project.
  6. Run the executable with least privilege and restrict its access to unrelated files, credentials, and network destinations.
  7. Avoid exposing credentials for providers that are not required for the current operation.
  8. Document which local file contents, URLs, metadata, and credentials may be sent to external model or extraction services.
  9. Periodically review the tap formula, upstream artifacts, maintainer ownership, signatures, and checksums for unauthorized changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly encourages summarizing URLs, local files, PDFs, images, audio, and YouTube content through third-party model providers, but it does not warn users that the referenced content and associated metadata may be transmitted to external services. This creates a real data exposure risk because users may submit sensitive internal documents, private files, or restricted URLs without understanding that their contents could leave the local environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.