T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Executable Installed from a Third-Party Homebrew Tap
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:5
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}Technical Analysis
The skill declares
steipete/tap/summarizeas its installation source. This is a third-party Homebrew tap, and the declaration does not pin an immutable version, source commit, artifact digest, or checksum.Consequently, the executable and installation procedure retrieved in the future may differ from those present when the skill was reviewed. Homebrew formula installation can execute build or installation logic, while the resulting
summarizeexecutable is subsequently trusted to process URLs, local files, and credentials supplied through provider environment variables. The project contains no executable source that would allow the installed behavior to be verified from this package alone.Attack Path
- An attacker compromises the third-party tap, its upstream release infrastructure, or an authorized publishing account.
- The attacker modifies the mutable formula or referenced artifact to contain malicious installation logic or a malicious
summarizeexecutable. - A user or agent loads the skill on a system where the required binary is absent and installs the declared formula.
- Homebrew retrieves and executes the modified installation content.
- When the installed CLI is invoked, the malicious executable runs with the invoking user's privileges.
- It can access input files passed for summarization and potentially read provider credentials available in the process environment, including the documented OpenAI, Anthropic, xAI, Google, Firecrawl, and Apify tokens.
This exploitation path is conditional on compromise or mal ...[truncated 762 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specific, reviewed release rather than relying on the current state of a mutable tap.
- Pin the underlying source artifact by a cryptographic SHA-256 digest and ensure the Homebrew formula verifies that digest before installation.
- Where supported, reference an immutable source commit or release identifier and document the exact audited version.
- Prefer an official, authenticated distribution channel over a third-party tap. If the tap remains necessary, document its trust basis and ownership.
- Verify release signatures or attestations and adopt provenance checks such as SLSA-compatible build attestations where available.
- Review formula changes and upstream release changes before updating the pinned dependency.
- Run the CLI with least privilege, expose only the API credential required for the selected provider, and avoid passing sensitive files unless necessary.
- Consider packaging reviewable source or a reproducible build definition with the skill so the installed executable can be independently validated.
