Back to skill

Security audit

Meta Business CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its Meta automation purpose, but it needs review because it installs unaudited CLI code and handles powerful Meta credentials, messages, webhooks, and long-running services with weak safety scoping.

Install only if you trust the CLI publisher and are comfortable granting it access to your Meta business assets. Prefer a pinned, reviewed release or verified source commit, avoid pasting production secrets into shared terminals or logs, check permissions on `~/.meta-cli/config.json`, and enable webhook forwarding or the systemd service only when you understand what message data will be sent and how to stop or uninstall it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:25
Finding

Unpinned Third-Party CLI Installation Enables Supply-Chain Compromise

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–35
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: High

Vulnerable Code

yaml
requires:
  bins: [meta]
install:
  - id: bun
    kind: command
    command: "bun install -g meta-business-cli"
    bins: [meta]
    label: "Install meta CLI (bun)"
  - id: compile
    kind: command
    command: "git clone https://github.com/adolago/meta-cli.git && cd meta-cli && bun install && bun build --compile --outfile ~/.bun/bin/meta src/index.ts"
    bins: [meta]
    label: "Build from source (standalone binary)"

Technical Analysis

Both installation methods retrieve mutable third-party content without pinning an exact package version, immutable Git commit, dependency lockfile state, or cryptographic integrity value.

The first method installs the currently resolved release of meta-business-cli. The second clones the current default branch of an external repository, installs its transitive dependencies, compiles the fetched source, and writes the resulting executable to ~/.bun/bin/meta. Consequently, the code executed by users can differ from the code available when this Skill was reviewed.

The project contains only SKILL.md; it does not include the CLI source or its dependency tree. The audit therefore cannot verify package lifecycle scripts, build behavior, credential storage, network destinations, or runtime handling of Meta account data.

Attack Path

  1. An attacker compromises the package registry entry, upstream repository, maintainer account, release process, or a transitive dependency.
  2. The attacker publishes malicious code under the same package name or places it on the repository’s mutable default branch.
  3. A user installs the Skill dependency through either documented installation command.
  4. bun install executes dependency installation logic, or the sourc ...[truncated 1003 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin meta-business-cli to an explicitly reviewed version rather than resolving the latest available release.
  • Pin source installations to a full immutable Git commit hash and verify that the commit belongs to an authenticated release.
  • Commit and enforce a dependency lockfile using frozen or immutable installation mode.
  • Publish expected cryptographic checksums or signatures for the package and compiled binary, and verify them before execution.
  • Disable dependency lifecycle scripts where feasible, or audit every required lifecycle script before allowing it to run.
  • Build the executable in an isolated, least-privileged environment without access to user credentials.
  • Prefer distributing a reproducible, signed artifact generated from audited source.
  • Review and update the pinned dependency deliberately instead of automatically consuming mutable upstream content.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Sensitive Credentials Are Passed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–59; additional occurrences at lines 210 and 258
Vulnerability Type: Exposure of secrets through process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
# 1. Configure app credentials
meta config set app.id YOUR_APP_ID
meta config set app.secret YOUR_APP_SECRET

# 2. Authenticate (OAuth PKCE, opens browser)
meta auth login

# 3. Configure WhatsApp (from API Setup page)
meta config set whatsapp.phoneNumberId YOUR_PHONE_NUMBER_ID
meta config set whatsapp.businessAccountId YOUR_WABA_ID

# 4. Verify everything works
meta doctor
bash
meta auth login                              # OAuth PKCE flow (opens browser)
meta auth login --token YOUR_ACCESS_TOKEN    # Use existing token
meta auth login --scopes "whatsapp_business_messaging,instagram_basic,pages_show_list"
bash
meta webhook listen --port 3000 --verify-token TOKEN --app-secret SECRET
text
| `--token TOKEN` | Override stored credentials |

Technical Analysis

The documented workflows supply application secrets, OAuth access tokens, and webhook secrets directly as command-line arguments. Depending on the operating system and execution environment, command arguments may be exposed through:

  • Shell history files.
  • Process inspection interfaces and process-monitoring utilities.
  • Terminal session recording.
  • CI/CD command logs.
  • Automation telemetry and debugging output.
  • Wrapper scripts or audit systems that record complete command lines.

Placeholder values do not constitute hardcoded credentials, but users are explicitly instructed to replace them with real secrets in the same command positions. The exposure occurs once those documented examples are used with production values.

Attack Path

  1. A user follows the documentation and substitutes a real application secret, access token, or webhook secret ...[truncated 1540 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace command-line secret arguments with input from a protected file, standard input, or an interactive prompt that disables terminal echo.
  • Store long-lived credentials in an operating-system keyring or dedicated secrets manager.
  • If environment-based injection is unavoidable, scope it to the child process and document that environment variables may also be observable in some environments.
  • Support file-based options such as --token-file and --app-secret-file, with strict permission checks before reading.
  • Ensure configuration files containing credentials are created with owner-only permissions, such as mode 0600.
  • Redact secrets from normal output, verbose diagnostics, exceptions, telemetry, and service logs.
  • Prevent sensitive commands from being persisted in shell history and clearly warn users not to place production credentials directly in command arguments.
  • Use narrowly scoped and short-lived access tokens wherever possible.
  • Document immediate credential rotation and revocation procedures for suspected exposure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very broad terms like "instagram," "facebook," "meta," and the generic action phrase "send message," which can cause the skill to be invoked in contexts far beyond the user's intent. Because this skill can send messages, post content, manage webhooks, and alter service state, accidental invocation materially increases the chance of unintended external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs users to set app secrets and access tokens and notes that configuration is stored at ~/.meta-cli/config.json, but it does not warn about secret sensitivity, local storage risk, or safe handling practices. This increases the likelihood that long-lived credentials are stored insecurely, exposed in shell history, logs, screenshots, or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents forwarding inbound webhook messages to an external URL without warning that message content and metadata may be transmitted to third-party infrastructure. In a messaging automation context, that can expose private customer communications or regulated data if users enable forwarding without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

Facebook Pages

bash
meta fb post --message "Hello from the CLI" --json           # Create post
meta fb post --message "Check this" --link "https://example.com" --json  # Link post
meta fb list --limit 10 --json                               # List posts
meta fb insights --period day --days 30 --json               # View insights

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically sending read receipts and reaction acknowledgements creates side effects on inbound messages without prominently warning the operator. This can leak activity status, alter customer-visible state, and trigger unintended business or compliance consequences in environments where message handling must remain manual or audited.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

Bash

meta completion >> ~/.bashrc

Zsh (add to .zshrc)

meta completion >> ~/.zshrc

text

Static analysis

No suspicious patterns detected.