T08 · Insecure Dependencies
- Location
SKILL.md:110- Finding
Unverified Third-Party CLI Is Granted Access to Sensitive Mailbox Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 110–112
Vulnerability Type: Supply-chain risk from an unverified third-party dependency
Risk Level: MediumVulnerable Code
markdown ## 前置依赖 1. 安装 porteden CLI:`brew install porteden/tap/porteden` 2. 登录:`porteden auth login` 打开浏览器,凭证存入系统 keyring 3. 验证:`porteden auth status`The installation command is also repeated at
SKILL.md:34andSKILL.md:172.Technical Analysis
The Skill directs the user or agent to install
portedenfrom the custom Homebrew tapporteden/tap. It then instructs the user to authenticate the installed program to Gmail or Outlook, with credentials stored through the system keyring.No immutable version, formula revision, package checksum, release signature, authoritative source repository, or other integrity-verification mechanism is specified. Consequently, the code ultimately installed and executed can change after this Skill has been reviewed. A compromise of the tap, formula, release hosting infrastructure, or publisher account could therefore introduce malicious installation or runtime behavior.
This dependency operates across a high-sensitivity trust boundary: it receives access to private mailbox metadata and content and participates in the authentication flow. Although no malicious implementation is included in the audited project, the documented installation process does not adequately establish the integrity of the component receiving that access.
Attack Path
-
An attacker compromises the custom Homebrew tap, its publisher account, the formula, or an artifact referenced by the formula.
-
The attacker modifies the package or installation definition to distribute a malicious
portedenexecutable. -
A user or agent follows the Skill instructions and runs:
bash brew install porteden/tap/porteden -
The malicious executable runs with the privileges of the invoking user.
-
The user follows the authentication instr ...[truncated 1035 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a reviewed, immutable version and, where possible, an immutable Homebrew formula revision or commit.
- Publish the authoritative source repository and official release location in the Skill documentation.
- Verify the downloaded artifact using a publisher signature or a documented SHA-256 checksum before execution.
- Review the Homebrew formula for installation hooks, dynamically retrieved resources, and mutable download URLs.
- Document the exact Gmail and Outlook authorization scopes requested by the CLI.
- Require least-privilege, read-only mailbox scopes consistent with the advertised functionality.
- Provide explicit procedures for revoking OAuth grants, invalidating API keys, and removing keyring credentials.
- Recommend installation and initial verification in a restricted environment before granting access to a production mailbox.
- Remove the declared
writetool permission if it is unnecessary for the read-only workflow. - Resolve the inconsistent credential variable names (
API_KEYandPE_API_KEY) and document secure secret handling without printing or persisting secrets in plaintext.
