T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Installation of a Security-Sensitive Third-Party CLI
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6 and 12
Vulnerability Type: Unpinned third-party dependency from mutable sources
Risk Level: MediumVulnerable Code
text metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}shell brew install porteden/tap/porteden # or go install github.com/porteden/cli/cmd/porteden@latestTechnical Analysis
The skill instructs users or agents to install the
portedenCLI through a custom Homebrew tap or by using Go's mutable@latestversion selector. It does not pin an immutable release or commit and provides no checksum, signature, provenance, or integrity-verification procedure.Because the installed CLI processes
PE_API_KEY, can read credentials from the system keyring, and receives authorized Google Drive access, compromise or unexpected modification of the upstream repository, release pipeline, module, or Homebrew tap would have security consequences beyond an ordinary utility dependency.The use of
@latestmeans that the installed artifact can change after this skill has been reviewed. The custom Homebrew source similarly relies on upstream package integrity without a verification step. The audit found no evidence that the currently referenced package is malicious; the vulnerability is the unsafe and mutable dependency acquisition process.Attack Path
- An attacker compromises the upstream Go repository, module release process, custom Homebrew tap, or associated distributio ...[truncated 1431 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a specific, reviewed semantic version or immutable commit digest, for example:shell go install github.com/porteden/cli/cmd/porteden@vX.Y.Z - Pin the Homebrew formula to an approved release where practical, and document the expected formula source and version.
- Publish trusted SHA-256 checksums or cryptographic signatures through a channel independent of the downloadable artifact.
- Verify checksums, signatures, and release provenance before installation.
- Prefer reproducible builds and signed release artifacts from an official, verifiable distribution source.
- Define an update-review process so dependency upgrades are explicitly audited rather than automatically resolved.
- Document the exact OAuth scopes and token restrictions required, and grant only the minimum Drive permissions needed.
- Avoid exposing
PE_API_KEYto unrelated child processes and use a protected system keyring where possible. - Instruct users to review
accessInfoand authentication warnings before performing sensitive operations. - Retain confirmation requirements for sharing and deletion operations.
- Replace
