Back to skill

Security audit

Frappecli

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes an ERP management CLI, but it gives an agent broad production data-changing and RPC powers without enough guardrails.

Review this before installing as an ERP administration tool, not a read-only helper. Use least-privileged API credentials, prefer staging for testing, verify or pin the CLI source, protect the config file, and require explicit approval before updates, deletes, uploads, report exports, or RPC calls on production systems.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party CLI Installation from Mutable Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-20
Vulnerability Type: Unverified and unpinned third-party dependency installation
Risk Level: Medium

bash
brew tap pasogott/tap
brew install frappecli
bash
git clone https://github.com/pasogott/frappecli.git
cd frappecli && uv sync && uv pip install -e .

Technical Analysis

The documented installation procedures retrieve and install executable software from mutable third-party sources. The Homebrew method trusts an externally controlled personal tap and its current formula, while the source installation clones the repository's current default branch and installs its dependency set with uv sync.

Neither method pins an immutable release or commit, verifies a checksum or cryptographic signature, or otherwise confirms that the downloaded code matches a reviewed artifact. The CLI source, formula, dependency manifests, and lock data are not present in the audited project, so their integrity and behavior cannot be established from this package.

This creates a supply-chain trust boundary: compromise or malicious modification of the repository, Homebrew tap, formula, release artifacts, or transitive dependencies could cause users to install attacker-controlled code.

Attack Path

  1. An attacker compromises or gains publishing access to the upstream repository, Homebrew tap, package source, or one of its unpinned dependencies.
  2. The attacker modifies the retrieved code, formula, or dependency to include a malicious installation or runtime payload.
  3. A user follows the instructions in SKILL.md and executes either the Homebrew commands or the unpinned clone-and-install commands.
  4. The mutable upstream source resolves to the attacker's modified content.
  5. Malicious code executes during installation or when the CLI is subsequently invoked.
  6. The altered CLI accesses credentials from the user's Frappe CLI configuration or abuses the user's authorized ERP operations.

...[truncated 785 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin installation instructions to a reviewed, immutable release and commit hash rather than the current default branch.

  2. Publish cryptographic checksums for release artifacts and require users to verify them before installation.

  3. Sign releases and Homebrew formula updates using a documented, verifiable signing process.

  4. Pin all direct and transitive dependencies and maintain a reviewed lockfile.

  5. Prefer an official, independently verifiable package distribution channel over a mutable personal tap.

  6. If source installation remains supported, use an immutable reference, for example:

    bash
    git clone https://github.com/pasogott/frappecli.git
    cd frappecli
    git checkout --detach <reviewed-commit-hash>
    git verify-commit <reviewed-commit-hash>
    uv sync --frozen
    
  7. Document a controlled dependency review and update process, including provenance checks, vulnerability scanning, and integrity validation before changing pinned versions.

  8. Instruct users to grant the CLI a least-privileged ERP API account and protect its configuration file with restrictive filesystem permissions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents a destructive delete command against a live Frappe/ERPNext instance without any warning, confirmation guidance, or safer alternatives. In an agent context, this increases the chance of accidental or over-broad data deletion because the command can be copied or suggested directly against production records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes arbitrary remote RPC method invocation without warning about trust boundaries, side effects, or the danger of calling custom server methods. Because RPC methods may trigger privileged actions, data modification, or business logic execution on a remote ERP system, an agent or user could unintentionally execute sensitive operations on production.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.