T08 · Insecure Dependencies
- Location
references/fulcra-cli.md:9- Finding
Unpinned Third-Party Package Is Dynamically Retrieved and Executed
- Content
View full analysis
--poll-timeout=5 ``` ### Technical Analysis The Skill instructs the Agent to use `uv tool run fulcra-api` without specifying a reviewed package version, artifact hash, lock file, or trusted package-index configuration. This command can dynamically resolve, download, install, and execute the package available from the configured Python package source at invocation time. Consequently, the code executed by the Skill can change after the Skill itself has been reviewed. A compromised maintainer account, malicious package release, package-index compromise, dependency-confusion condition, or unsafe custom index could cause attacker-controlled code to execute locally. The linked source repository does not ensure that the dynamically resolved package is built from a particular reviewed commit. The project also provides no integrity verification tying the downloaded artifact to that repository. ### Attack Path 1. An attacker compromises the `fulcra-api` distribution, one of its transitive dependencies, its publishing account, or a package source configured in the execution environment. 2. The attacker publishes a malicious version that satisfies the unconstrained package resolution request. 3. A user or Agent follows the Skill instructions and runs `uv tool run fulcra-api`. 4. `uv` retrieves and executes the attacker-controlled package wi ...[truncated 1327 chars]- Remediation
View remediation
' ``` 2. Use a lock file or verified artifact with cryptographic hashes so package content cannot change without an explicit review. 3. Explicitly configure and document the trusted package index. Do not permit fallback to arbitrary or user-controlled indexes when executing the package. 4. Verify that the published artifact corresponds to a reviewed source commit, preferably through signed releases, provenance attestations, and reproducible-build metadata. 5. Review and pin transitive dependencies, not only the top-level `fulcra-api` package. 6. Obtain explicit user approval before the first package download or execution, explaining that third-party code will execute with the user account’s local permissions. 7. Where practical, run the CLI in a restricted environment with: - Minimal filesystem access. - No unrelated secrets in environment variables. - Restricted outbound network access. - A dedicated low-privilege operating-system account. - Narrowly scoped Fulcra authorization. 8. Ensure `~/.config/fulcra/credentials.json` is created with owner-only permissions and avoid exposing its contents through logs, command output, or shared working directories. ]]>
