Back to skill

Security audit

Flue - Control Desktop Software

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed bootstrap guide for a desktop-automation package, with explicit user approval required before installation or setup.

Before installing, inspect the linked Flue project and consider pinning a reviewed version or installing in an isolated environment. Only approve `flue setup` if you understand what integrations it will add to your desktop applications.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:78
Finding

Unpinned Third-Party Package Installation and Immediate Setup Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 78
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code:

text
If Flue appears relevant but is not available on the machine, tell your human as much. Inspect the project at `https://github.com/SFKislev/flue` (PyPI: `https://pypi.org/project/flue`). Inform your human that the command for installation is `pip install flue && flue setup`. Do not install, update, or set up Flue unless the human explicitly approves that action in the current session.

Technical Analysis

The recommended command installs the latest package release resolved under the unpinned PyPI name flue and then immediately invokes its setup entry point. The project supplies no fixed version, package hash, lockfile, signature-verification procedure, vendored source, or other integrity control tying installation to a reviewed artifact.

Consequently, the effective code installed and executed can differ from the content originally reviewed. Requiring explicit user approval is a useful operational safeguard, but it does not establish package authenticity or release integrity.

Attack Path

  1. An attacker compromises the package publisher account, distribution infrastructure, or another relevant supply-chain component.
  2. The attacker publishes or substitutes a malicious release under the package name resolved by pip install flue.
  3. A user requests desktop-application automation on a system where Flue is unavailable.
  4. Following the Skill's guidance, the agent presents the installation command and obtains current-session user approval.
  5. pip install flue downloads and installs the attacker-controlled release.
  6. The chained flue setup command immediately runs the installed package's entry point.
  7. Malicious package code executes with the operating-system privileges and accessible resources of the invoking user.

Impa

...[truncated 770 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release, for example by using an exact version rather than an unconstrained package name.
  2. Publish and verify cryptographic hashes for the package and all transitive dependencies, preferably through a hash-locked requirements file.
  3. Separate package installation from flue setup so users can inspect the installed artifact, provenance, entry points, and requested changes before executing setup.
  4. Provide reproducible provenance information linking the PyPI artifact to a reviewed source commit and release tag.
  5. Recommend installation in an isolated virtual environment and execution under a least-privileged account.
  6. Document what flue setup changes, including files, application integrations, services, permissions, and network operations.
  7. Preserve the existing requirement for explicit current-session user approval, while clarifying that approval should cover both installation and the subsequent setup operation independently.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.