Back to skill

Security audit

Fpt Cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for using fpt-cli with ShotGrid, but its Windows install and update guidance can run or replace a local binary without strong verification while the tool later handles sensitive credentials.

Install only from a release and platform you trust. On Windows, verify the release archive through a trusted checksum or signature before running fpt.exe, and avoid unattended self-updates unless your organization accepts that supply-chain risk. Use least-privileged ShotGrid credentials, prefer secret managers or protected CI variables over pasted shell exports, and review dry-run output before allowing real writes or deletes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
references/install-and-auth.md:43
Finding

Unverified Windows Binary Download and Execution

Content
View full analysis
Remediation
View remediation
" Invoke-WebRequest ` -Uri "https://github.com/loonghao/fpt-cli/releases/download/$FptVersion/$Archive" ` -OutFile $Archive $ActualSha256 = (Get-FileHash -Algorithm SHA256 -Path $Archive).Hash.ToLowerInvariant() if ($ActualSha256 -ne $ExpectedSha256.ToLowerInvariant()) { Remove-Item -Force $Archive throw "fpt-cli archive checksum verification failed" } # Extract, install, and execute only after successful verification. ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The documented fpt self update command causes the tool to modify its own installed binary in place, which is a self-modification capability. In an agent context, allowing unattended self-update can bypass normal change control, introduce unreviewed code, and expand supply-chain risk if the update source or verification path is compromised.

Content

Scanner excerpt · references/install-and-auth.md (reported line 47)May include surrounding context.

text

### In-place update
Use the released binary's self-update command when `fpt` is already installed.

```bash
fpt self update --check --output pretty-json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The authentication sections instruct users to place passwords, script keys, and session tokens directly into environment variables and shell examples without any explicit warning about secret exposure risks. In agent or shared-host environments, these values may be captured in shell history, terminal logs, CI logs, process snapshots, or inherited environments, increasing the chance of credential disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.