T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party CLI Installation from Mutable Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-20
Vulnerability Type: Unverified and unpinned third-party dependency installation
Risk Level: Mediumbash brew tap pasogott/tap brew install frappeclibash git clone https://github.com/pasogott/frappecli.git cd frappecli && uv sync && uv pip install -e .Technical Analysis
The documented installation procedures retrieve and install executable software from mutable third-party sources. The Homebrew method trusts an externally controlled personal tap and its current formula, while the source installation clones the repository's current default branch and installs its dependency set with
uv sync.Neither method pins an immutable release or commit, verifies a checksum or cryptographic signature, or otherwise confirms that the downloaded code matches a reviewed artifact. The CLI source, formula, dependency manifests, and lock data are not present in the audited project, so their integrity and behavior cannot be established from this package.
This creates a supply-chain trust boundary: compromise or malicious modification of the repository, Homebrew tap, formula, release artifacts, or transitive dependencies could cause users to install attacker-controlled code.
Attack Path
- An attacker compromises or gains publishing access to the upstream repository, Homebrew tap, package source, or one of its unpinned dependencies.
- The attacker modifies the retrieved code, formula, or dependency to include a malicious installation or runtime payload.
- A user follows the instructions in
SKILL.mdand executes either the Homebrew commands or the unpinned clone-and-install commands. - The mutable upstream source resolves to the attacker's modified content.
- Malicious code executes during installation or when the CLI is subsequently invoked.
- The altered CLI accesses credentials from the user's Frappe CLI configuration or abuses the user's authorized ERP operations.
...[truncated 785 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin installation instructions to a reviewed, immutable release and commit hash rather than the current default branch.
-
Publish cryptographic checksums for release artifacts and require users to verify them before installation.
-
Sign releases and Homebrew formula updates using a documented, verifiable signing process.
-
Pin all direct and transitive dependencies and maintain a reviewed lockfile.
-
Prefer an official, independently verifiable package distribution channel over a mutable personal tap.
-
If source installation remains supported, use an immutable reference, for example:
bash git clone https://github.com/pasogott/frappecli.git cd frappecli git checkout --detach <reviewed-commit-hash> git verify-commit <reviewed-commit-hash> uv sync --frozen -
Document a controlled dependency review and update process, including provenance checks, vulnerability scanning, and integrity validation before changing pinned versions.
-
Instruct users to grant the CLI a least-privileged ERP API account and protect its configuration file with restrictive filesystem permissions.
-
