Back to skill

Security audit

folk CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for managing Folk CRM data, but it routes a powerful CRM API key through a globally installed third-party GitHub CLI with broad read and mutation abilities.

Install only if you trust the pinned folkctl source and are comfortable giving it API access to your Folk workspace. Use a narrowly scoped or dedicated API key if available, verify the CLI version before setting FOLK_API_KEY, prefer dry-runs before changes, avoid storing the token unless needed, and rotate the key if unexpected activity appears.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:170
Finding

Unverified Third-Party CLI Receives Privileged CRM Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 6 and 170–175
Vulnerability Type: Supply-chain exposure through an externally hosted privileged dependency
Risk Level: Medium

The skill declares and globally installs folkctl directly from a personal GitHub repository at a pinned commit:

json
"install":[{"kind":"node","package":"github:j-edel/folkctl#4a9c2af28427432beee018561f5f43e3ecfc2645","bins":["folkctl"]}]
bash
npm install -g --ignore-scripts github:j-edel/folkctl#4a9c2af28427432beee018561f5f43e3ecfc2645
folkctl --version

Technical Analysis

The installed CLI is not included in the audited project and is sourced from a repository that is not shown to be controlled by folk.app. The skill subsequently instructs users to expose FOLK_API_KEY to this executable, enabling authenticated reads and mutations of CRM data.

Pinning a full commit hash limits unintended version drift, while --ignore-scripts reduces npm lifecycle-script exposure. However, these controls do not establish that the pinned source itself is trustworthy or safe. The current artifact does not contain the CLI implementation, package metadata, provenance attestations, or an independently verified archive checksum. Consequently, claims that the CLI has no runtime dependencies or harmful behavior cannot be independently validated from the audited project.

No evidence establishes that the referenced dependency is malicious. The confirmed issue is that an externally sourced and unaudited executable is placed across a security boundary and entrusted with a live bearer token and broad CRM operations.

Attack Path

  1. An operator installs the GitHub-hosted package globally as instructed by the skill.
  2. The installed package registers the folkctl executable on the host.
  3. The operator makes FOLK_API_KEY available in the executable's environment.
  4. If the pinned external source contains compromised or unsaf ...[truncated 1099 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor the reviewed folkctl source into the audited artifact or distribute it through an official, organization-controlled release channel.
  2. Audit the exact pinned CLI source, package manifest, transitive dependencies, and generated executable before granting it access to credentials.
  3. Publish and verify a cryptographic checksum for a deterministic release archive rather than relying only on a Git commit reference.
  4. Add provenance attestations and signed releases so consumers can verify the publisher and build origin.
  5. Avoid global installation where possible. Run the CLI in an isolated environment or container with minimal filesystem and network access.
  6. Issue a narrowly scoped API credential with only the permissions required for the requested task. Use short-lived credentials where supported.
  7. Provide the credential only after installation and integrity verification, as the skill already recommends, and remove it from the environment immediately after use.
  8. Restrict outbound network access to approved folk.app endpoints to reduce credential-exfiltration opportunities.
  9. Ensure any supported FOLK_API_BASE_URL override is administrator-controlled, requires HTTPS, and is validated against an explicit allowlist before an authorization token is attached.
  10. Monitor CRM audit logs, rotate the credential after suspected exposure, and revoke it immediately if unexpected API activity is observed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.