T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unverified Third-Party Homebrew Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}Technical Analysis
The skill directs users or an agent-managed installation process to install the
summarizeexecutable from the third-party Homebrew tapsteipete/tap. The formula, executable source, artifact checksum, and immutable version are not included in the audited project. Consequently, the behavior and integrity of the installed component cannot be verified from this package.Using a mutable, externally maintained package source creates a supply-chain trust boundary. If the tap, its maintainer account, the referenced release infrastructure, or downloaded artifacts are compromised, installation may deliver code that differs from the code originally reviewed. The project does not pin an immutable formula revision or independently verify an expected artifact digest.
This finding does not establish that the current third-party formula is malicious. It identifies that the skill delegates executable installation to an unreviewed external source without integrity controls visible in the audited files.
Attack Path
- An attacker compromises the third-party Homebrew tap, its maintainer credentials, or an artifact distribution endpoint used by the formula.
- The attacker modifies the formula or a referenced binary/archive to include malicious installation or runtime behavior.
- A user or agent loads the skill and follows its declared installation metadata to obtain the missing
summarizeexecutable. - Homebrew resolves and executes the third-party formula and downloads the attacker-controlled component.
- The malicious installati ...[truncated 780 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an immutable, reviewed release rather than a mutable tap reference.
- Verify downloaded artifacts against a cryptographic SHA-256 or stronger digest maintained in a trusted location.
- Vendor the formula and relevant executable source into a reviewable repository, or use a trusted package registry with provenance and signing support.
- Require signed releases and verify signatures before installation.
- Run installation and execution with least privilege; do not use an administrator account unless strictly necessary.
- Restrict the CLI process to only the files, environment variables, and network destinations required for summarization.
- Add automated dependency provenance checks, checksum validation, and periodic review of the upstream formula and release artifacts.
- Clearly disclose that URLs, local files, and potentially sensitive content may be processed by external model or extraction providers before users invoke the tool.
