T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party CLI Receives Sensitive Google Calendar Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5–11
Vulnerability Type: Unpinned third-party dependency and mutable supply-chain installation
Risk Level: HighThe Skill directs users to install the externally maintained
portedenexecutable from a custom Homebrew tap or directly from the latest revision of a GitHub-hosted Go module:yaml metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}markdown If `porteden` is not installed: `brew install porteden/tap/porteden` (or `go install github.com/porteden/cli/cmd/porteden@latest`).Technical Analysis
The Go installation explicitly uses
@latest, while the custom Homebrew formula also lacks an immutable version, commit, checksum, or signature requirement in the Skill. Consequently, the executable installed at a future date may differ from the artifact that was originally reviewed.This is security-sensitive because the CLI is subsequently entrusted with a
PE_API_KEYor credentials stored throughporteden auth login. Its declared operation also exposes private calendar information to the executable, potentially including event descriptions, attendee email addresses, locations, meeting URLs, account identifiers, and availability data. It is also able to perform state-changing operations such as creating, updating, deleting, and responding to events.The document contains useful safeguards, including confirmation before mutations, account profiles, logout ...[truncated 2453 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an explicitly audited, immutable semantic version or commit:bash go install github.com/porteden/cli/cmd/porteden@vX.Y.Z - Pin the Homebrew installation to a versioned formula or bottle rather than relying on a mutable custom-tap head.
- Publish and verify cryptographic checksums or signatures before installation. Record the expected digest in reviewed Skill metadata or installation documentation.
- Prefer an official, reproducible distribution channel with provenance attestations, signed releases, and a documented vulnerability response process.
- Document every network endpoint contacted by the CLI and explain whether calendar data passes directly to Google or through an intermediary service.
- Document the precise OAuth scopes requested. Use read-only Calendar scopes by default and require a separate, explicit authorization step before granting mutation capabilities.
- Isolate accounts with
--profileorPE_PROFILE, and authorize only the specific Google account and calendars required for the task. - Avoid exposing credentials through broadly inherited process environments where possible. Continue storing credentials in a protected OS keyring, restrict access permissions, and revoke tokens after suspected exposure.
- Add dependency update review procedures so each version change triggers source review, provenance verification, and security testing before the pinned version is updated.
- Retain the existing confirmation requirements, but do not treat them as a defense against compromised dependency code.
- Replace
