T08 · Insecure Dependencies
- Location
SKILL.md:170- Finding
Unverified Third-Party CLI Receives Privileged CRM Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6 and 170–175
Vulnerability Type: Supply-chain exposure through an externally hosted privileged dependency
Risk Level: MediumThe skill declares and globally installs
folkctldirectly from a personal GitHub repository at a pinned commit:json "install":[{"kind":"node","package":"github:j-edel/folkctl#4a9c2af28427432beee018561f5f43e3ecfc2645","bins":["folkctl"]}]bash npm install -g --ignore-scripts github:j-edel/folkctl#4a9c2af28427432beee018561f5f43e3ecfc2645 folkctl --versionTechnical Analysis
The installed CLI is not included in the audited project and is sourced from a repository that is not shown to be controlled by folk.app. The skill subsequently instructs users to expose
FOLK_API_KEYto this executable, enabling authenticated reads and mutations of CRM data.Pinning a full commit hash limits unintended version drift, while
--ignore-scriptsreduces npm lifecycle-script exposure. However, these controls do not establish that the pinned source itself is trustworthy or safe. The current artifact does not contain the CLI implementation, package metadata, provenance attestations, or an independently verified archive checksum. Consequently, claims that the CLI has no runtime dependencies or harmful behavior cannot be independently validated from the audited project.No evidence establishes that the referenced dependency is malicious. The confirmed issue is that an externally sourced and unaudited executable is placed across a security boundary and entrusted with a live bearer token and broad CRM operations.
Attack Path
- An operator installs the GitHub-hosted package globally as instructed by the skill.
- The installed package registers the
folkctlexecutable on the host. - The operator makes
FOLK_API_KEYavailable in the executable's environment. - If the pinned external source contains compromised or unsaf ...[truncated 1099 chars]
- Remediation
View remediation
Remediation Suggestions
- Vendor the reviewed
folkctlsource into the audited artifact or distribute it through an official, organization-controlled release channel. - Audit the exact pinned CLI source, package manifest, transitive dependencies, and generated executable before granting it access to credentials.
- Publish and verify a cryptographic checksum for a deterministic release archive rather than relying only on a Git commit reference.
- Add provenance attestations and signed releases so consumers can verify the publisher and build origin.
- Avoid global installation where possible. Run the CLI in an isolated environment or container with minimal filesystem and network access.
- Issue a narrowly scoped API credential with only the permissions required for the requested task. Use short-lived credentials where supported.
- Provide the credential only after installation and integrity verification, as the skill already recommends, and remove it from the environment immediately after use.
- Restrict outbound network access to approved folk.app endpoints to reduce credential-exfiltration opportunities.
- Ensure any supported
FOLK_API_BASE_URLoverride is administrator-controlled, requires HTTPS, and is validated against an explicit allowlist before an authorization token is attached. - Monitor CRM audit logs, rotate the credential after suspected exposure, and revoke it immediately if unexpected API activity is observed.
- Vendor the reviewed
