T08 · Insecure Dependencies
- Location
SKILL.md:41- Finding
Unpinned and Unverified Third-Party CLI Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:41-45
Vulnerability Type: Supply-chain risk from an unpinned third-party dependency
Risk Level: MediumVulnerable Code
bash brew install porteden/tap/porteden # or go install 相关技术文档Related installation and authentication instructions also appear at
SKILL.md:120-126:text 1. Install porteden CLI: `brew install porteden/tap/porteden` 2. Login (choose one): - Browser login (recommended): `porteden auth login` - Direct token: `porteden auth login --token <key>` - Environment variable: set `PE_API_KEY`Technical Analysis
The Skill instructs the Agent to install and execute the third-party
portedenCLI from a Homebrew tap without pinning an immutable release, verifying a checksum or signature, or identifying a trusted source repository. The alternative Go installation command is incomplete and provides neither a module path nor a fixed version.The CLI is security-sensitive because it receives mailbox credentials and is authorized to read, send, reply to, forward, modify, and delete email. If the package source, tap, distribution account, or latest release is compromised, installation could introduce code different from the version originally reviewed.
This finding identifies a supply-chain weakness; the reviewed project does not contain evidence that the current package is malicious.
Attack Path
- An attacker compromises the third-party tap, package publication account, or upstream release channel.
- The attacker publishes a modified package under the expected dependency name.
- A user invokes the Skill on a system where
portedenis not installed. - The Agent follows the documented unpinned installation command.
- The package manager retrieves and executes the attacker-controlled version.
- The user authenticates the CLI to a Gmail, Outlook, or Exchange mailbox.
- The compromised CLI captures credentials or performs unauthorized mailbox ope ...[truncated 616 chars]
- Remediation
View remediation
Remediation Suggestions
- Identify and link the authoritative upstream source repository and package documentation.
- Pin installation to a reviewed, immutable release rather than implicitly installing the latest version.
- Publish and verify a cryptographic checksum or signed release artifact before execution.
- Replace the malformed Go example with a complete module path and fixed version, such as
module/path@vX.Y.Z, after verifying the actual upstream module. - Document the package publisher, expected signing identity, required mailbox scopes, and expected network destinations.
- Prefer installation through a trusted package repository with reproducible builds and provenance attestations.
- Re-audit the dependency before updating the pinned version.
