T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party CLI Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5 and 12
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code Snippets:
Line 5:
yaml metadata: {"openclaw":{"emoji":"📂","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}Line 12:
markdown If `porteden` is not installed: `brew install porteden/tap/porteden` (or `go install github.com/porteden/cli/cmd/porteden@latest`).Technical Analysis
The skill directs users or agents to install the third-party
portedenCLI without pinning it to a reviewed, immutable version. The Go installation explicitly uses the mutable@latestselector. The custom Homebrew tap similarly resolves whatever formula and release are current when installation occurs.This creates a time-of-review versus time-of-installation gap: the executable ultimately granted access to credentials and Google Drive data may differ from the version considered when the skill was audited. If the upstream repository, release pipeline, maintainer account, Go module, or Homebrew tap is compromised, an attacker can distribute modified code through the documented installation process.
Attack Path
- An attacker compromises the upstream repository, maintainer account, release process, Go module distribution path, or custom Homebrew tap.
- The attacker publishes a malicious release or modifies the package resolved by
@latestor the unversioned Homebrew formula. - A user o ...[truncated 1251 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
github.com/porteden/cli/cmd/porteden@latestwith a specific reviewed semantic version or immutable commit. - Provide a version-pinned installation path for Homebrew rather than relying on the mutable current formula.
- Publish and verify cryptographic checksums or signatures for the expected executable before first use.
- Document the exact supported CLI version in the skill metadata and installation instructions.
- Use automated dependency monitoring to review updates before changing the pinned version.
- Prefer reproducible builds and provenance attestations, such as signed releases and verifiable build metadata.
- Run the CLI with the minimum necessary Google Drive scopes and a restricted token so that compromise has limited reach.
- Avoid exposing credentials to the process longer than necessary, and rotate the API key or revoke the connected session if dependency compromise is suspected.
- Replace
