Back to skill

Security audit

Summarize

Security checks for vulnerabilities and agentic risk

Overview

This summarization skill has a coherent purpose, but users should review it because it installs an unpinned third-party CLI and may send files, URLs, and media to external AI or extraction services.

Install only if you trust the Homebrew tap and the summarize CLI it provides. Do not use this skill on secrets, regulated data, private documents, or confidential URLs unless you are comfortable sending that content to the selected model provider and any enabled extraction services such as Firecrawl or Apify.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unverified Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"🧾","requires":{"bins":["summarize"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/summarize","bins":["summarize"],"label":"Install summarize (brew)"}]}}

Technical Analysis

The skill directs users or an agent-managed installation process to install the summarize executable from the third-party Homebrew tap steipete/tap. The formula, executable source, artifact checksum, and immutable version are not included in the audited project. Consequently, the behavior and integrity of the installed component cannot be verified from this package.

Using a mutable, externally maintained package source creates a supply-chain trust boundary. If the tap, its maintainer account, the referenced release infrastructure, or downloaded artifacts are compromised, installation may deliver code that differs from the code originally reviewed. The project does not pin an immutable formula revision or independently verify an expected artifact digest.

This finding does not establish that the current third-party formula is malicious. It identifies that the skill delegates executable installation to an unreviewed external source without integrity controls visible in the audited files.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer credentials, or an artifact distribution endpoint used by the formula.
  2. The attacker modifies the formula or a referenced binary/archive to include malicious installation or runtime behavior.
  3. A user or agent loads the skill and follows its declared installation metadata to obtain the missing summarize executable.
  4. Homebrew resolves and executes the third-party formula and downloads the attacker-controlled component.
  5. The malicious installati ...[truncated 780 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an immutable, reviewed release rather than a mutable tap reference.
  2. Verify downloaded artifacts against a cryptographic SHA-256 or stronger digest maintained in a trusted location.
  3. Vendor the formula and relevant executable source into a reviewable repository, or use a trusted package registry with provenance and signing support.
  4. Require signed releases and verify signatures before installation.
  5. Run installation and execution with least privilege; do not use an administrator account unless strictly necessary.
  6. Restrict the CLI process to only the files, environment variables, and network destinations required for summarization.
  7. Add automated dependency provenance checks, checksum validation, and periodic review of the upstream formula and release artifacts.
  8. Clearly disclose that URLs, local files, and potentially sensitive content may be processed by external model or extraction providers before users invoke the tool.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill encourages summarizing URLs, local files, PDFs, images, audio, and YouTube content using third-party model providers and optional extraction services, but it does not clearly warn users that submitted content may be transmitted off-device to external APIs. This creates a real privacy and data-handling risk because users may provide sensitive local files or confidential URLs without understanding that their contents could be sent to OpenAI, Anthropic, Google, xAI, Firecrawl, or Apify.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.