Back to skill

Security audit

tencentcli-test

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward wrapper for a summarization CLI, with notable privacy and supply-chain cautions but no artifact-backed evidence of hidden or malicious behavior.

Install only if you trust the Homebrew tap and the summarize CLI provider. Treat anything you summarize, including local files and fetched URL content, as potentially sent to the selected model provider or fallback service, and provide only the API keys needed for the provider you intend to use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}

Technical Analysis

The skill declares steipete/tap/summarize as its installation source. This is a third-party Homebrew tap, and the declaration does not pin an immutable version, source commit, artifact digest, or checksum.

Consequently, the executable and installation procedure retrieved in the future may differ from those present when the skill was reviewed. Homebrew formula installation can execute build or installation logic, while the resulting summarize executable is subsequently trusted to process URLs, local files, and credentials supplied through provider environment variables. The project contains no executable source that would allow the installed behavior to be verified from this package alone.

Attack Path

  1. An attacker compromises the third-party tap, its upstream release infrastructure, or an authorized publishing account.
  2. The attacker modifies the mutable formula or referenced artifact to contain malicious installation logic or a malicious summarize executable.
  3. A user or agent loads the skill on a system where the required binary is absent and installs the declared formula.
  4. Homebrew retrieves and executes the modified installation content.
  5. When the installed CLI is invoked, the malicious executable runs with the invoking user's privileges.
  6. It can access input files passed for summarization and potentially read provider credentials available in the process environment, including the documented OpenAI, Anthropic, xAI, Google, Firecrawl, and Apify tokens.

This exploitation path is conditional on compromise or mal ...[truncated 762 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific, reviewed release rather than relying on the current state of a mutable tap.
  2. Pin the underlying source artifact by a cryptographic SHA-256 digest and ensure the Homebrew formula verifies that digest before installation.
  3. Where supported, reference an immutable source commit or release identifier and document the exact audited version.
  4. Prefer an official, authenticated distribution channel over a third-party tap. If the tap remains necessary, document its trust basis and ownership.
  5. Verify release signatures or attestations and adopt provenance checks such as SLSA-compatible build attestations where available.
  6. Review formula changes and upstream release changes before updating the pinned dependency.
  7. Run the CLI with least privilege, expose only the API credential required for the selected provider, and avoid passing sensitive files unless necessary.
  8. Consider packaging reviewable source or a reproducible build definition with the skill so the installed executable can be independently validated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs users to summarize URLs, local files, and YouTube content via third-party model providers and optional fallback services, but it does not warn that the referenced content may be transmitted to external APIs. This creates a real privacy and data-handling risk because users may unknowingly send sensitive local files, proprietary documents, or restricted web content to OpenAI, Anthropic, Google, xAI, Firecrawl, or Apify.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.