<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://mediawiki.comfac.net/index.php?action=history&amp;feed=atom&amp;title=SOP%3A_Third-Party_Software_Security_Review</id>
	<title>SOP: Third-Party Software Security Review - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://mediawiki.comfac.net/index.php?action=history&amp;feed=atom&amp;title=SOP%3A_Third-Party_Software_Security_Review"/>
	<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=SOP:_Third-Party_Software_Security_Review&amp;action=history"/>
	<updated>2026-10-03T08:03:47Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://mediawiki.comfac.net/index.php?title=SOP:_Third-Party_Software_Security_Review&amp;diff=279&amp;oldid=prev</id>
		<title>Justinaquino: Create SOP: third-party software security review workflow + first due-diligence result (offline-browser-translate)</title>
		<link rel="alternate" type="text/html" href="https://mediawiki.comfac.net/index.php?title=SOP:_Third-Party_Software_Security_Review&amp;diff=279&amp;oldid=prev"/>
		<updated>2026-08-09T06:23:57Z</updated>

		<summary type="html">&lt;p&gt;Create SOP: third-party software security review workflow + first due-diligence result (offline-browser-translate)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= SOP: Third-Party Software Security Review (Due Diligence) =&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Purpose:&amp;#039;&amp;#039;&amp;#039; No third-party code — GitHub repos, browser extensions, open-source tools — is installed or run on Comfac machines without a security review first. The review emphasis is &amp;#039;&amp;#039;&amp;#039;data leakage / exfiltration risk&amp;#039;&amp;#039;&amp;#039;, then permissions vs. purpose, obfuscation, supply chain, and repository history.&lt;br /&gt;
&lt;br /&gt;
The full workflow, criteria, and triage script live in the IT-knowledge repo: &amp;lt;code&amp;gt;IT-knowledge/skills/repo-security-review/&amp;lt;/code&amp;gt; (git.gi7b.org). Finished review reports are filed in &amp;lt;code&amp;gt;IT-knowledge/skills/repo-security-review/reports/&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Workflow ==&lt;br /&gt;
&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Acquire and pin.&amp;#039;&amp;#039;&amp;#039; Clone full history into a scratch area (never a synced project folder). Record the exact commit (&amp;lt;code&amp;gt;git rev-parse HEAD&amp;lt;/code&amp;gt;) — the verdict covers that commit only.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Automated triage.&amp;#039;&amp;#039;&amp;#039; Run the pattern pack:&lt;br /&gt;
#: &amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;bash IT-knowledge/skills/repo-security-review/scripts/triage-scan.sh &amp;amp;lt;git-url&amp;amp;gt; agent260222/repo-scans&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
#: It scans for hardcoded endpoints, network calls, telemetry keywords, obfuscation/dynamic exec, remote code loading, dangerous extension APIs, data-at-rest, injection sinks, IPC/message surfaces, committed secrets, install/CI hooks, binaries, and contributor history. &amp;#039;&amp;#039;&amp;#039;A clean triage is not a verdict&amp;#039;&amp;#039;&amp;#039; — it finds where to look.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Manual review.&amp;#039;&amp;#039;&amp;#039; Read every triage hit in context; read the manifest/permissions and trace the data flow: what user data is read, where does every network call send, what persists. Every egress destination must be user-configured or justified by the feature — anything else is a finding.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Verdict and report.&amp;#039;&amp;#039;&amp;#039; File the report under &amp;lt;code&amp;gt;reports/YYMMDD-&amp;amp;lt;repo&amp;amp;gt;.md&amp;lt;/code&amp;gt; with target + commit, verdict, data-flow map, findings table (with file:line evidence), and caveats.&lt;br /&gt;
# &amp;#039;&amp;#039;&amp;#039;Re-review on change.&amp;#039;&amp;#039;&amp;#039; A verdict expires on update, permission/manifest change, ownership change, or a dependency adding a binary blob. Diff from the reviewed commit and re-triage the delta.&lt;br /&gt;
&lt;br /&gt;
== Criteria Checklist ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! # !! Question !! Fail closed when&lt;br /&gt;
|-&lt;br /&gt;
| 1 || Can you enumerate every network destination? || Hidden/encoded endpoints&lt;br /&gt;
|-&lt;br /&gt;
| 2 || Does every egress match the stated purpose? || Data leaves to a party the user didn&amp;#039;t configure&lt;br /&gt;
|-&lt;br /&gt;
| 3 || Is the permission set minimal for the purpose? || Broad grants (&amp;amp;lt;all_urls&amp;amp;gt;, filesystem, exec) without justification&lt;br /&gt;
|-&lt;br /&gt;
| 4 || Is all executed code readable? || Obfuscation, blobs without source, remote code loading&lt;br /&gt;
|-&lt;br /&gt;
| 5 || Does anything run before you consent? || postinstall hooks, curl&amp;amp;#124;sh installs, unpinned self-update&lt;br /&gt;
|-&lt;br /&gt;
| 6 || What user data is read and where is it stored? || Silent persistence of content/credentials&lt;br /&gt;
|-&lt;br /&gt;
| 7 || Are IPC/message boundaries validated? || Privileged handlers trusting unverified senders&lt;br /&gt;
|-&lt;br /&gt;
| 8 || Is the supply chain pinned? || Unpinned deps, unsigned release binaries&lt;br /&gt;
|-&lt;br /&gt;
| 9 || Does history/metadata support trust? || New owner + permission bump, throwaway account&lt;br /&gt;
|-&lt;br /&gt;
| 10 || Would you notice if an update turned evil? || Auto-update with no hash check&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Verdicts ==&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;CLEAN&amp;#039;&amp;#039;&amp;#039; — install OK.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;CLEAN WITH CONDITIONS&amp;#039;&amp;#039;&amp;#039; — install OK if the listed configuration conditions are met.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;SUSPICIOUS&amp;#039;&amp;#039;&amp;#039; — do not install; the report lists what would change the verdict.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;MALICIOUS&amp;#039;&amp;#039;&amp;#039; — do not install; consider reporting upstream.&lt;br /&gt;
&lt;br /&gt;
Severity: &amp;#039;&amp;#039;&amp;#039;Critical&amp;#039;&amp;#039;&amp;#039; (exfiltration, RCE, credential theft) · &amp;#039;&amp;#039;&amp;#039;High&amp;#039;&amp;#039;&amp;#039; (exfiltration capability gated only by config/obscurity, obfuscated payload) · &amp;#039;&amp;#039;&amp;#039;Medium&amp;#039;&amp;#039;&amp;#039; (over-broad permissions, cleartext transport of user content, missing origin checks) · &amp;#039;&amp;#039;&amp;#039;Low&amp;#039;&amp;#039;&amp;#039; (privacy footguns, hygiene) · &amp;#039;&amp;#039;&amp;#039;Info&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
== Review Log ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Date !! Target !! Commit !! Verdict !! Report&lt;br /&gt;
|-&lt;br /&gt;
| 2026-08-09 || [https://github.com/Eldoprano/offline-browser-translate offline-browser-translate] (Firefox extension, local-LLM page translation) || d2b0907 || &amp;#039;&amp;#039;&amp;#039;CLEAN WITH CONDITIONS&amp;#039;&amp;#039;&amp;#039; || IT-knowledge: &amp;lt;code&amp;gt;skills/repo-security-review/reports/260809-offline-browser-translate.md&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 2026-08-09 — offline-browser-translate (Local LLM Translator) ===&lt;br /&gt;
&lt;br /&gt;
Static review of all source (60 commits, full history) at commit &amp;lt;code&amp;gt;d2b0907&amp;lt;/code&amp;gt;. No exfiltration, no telemetry, no obfuscation, no remote code loading, no dependencies or install hooks. The extension&amp;#039;s &amp;quot;your data never leaves your machine&amp;quot; claim is accurate &amp;#039;&amp;#039;&amp;#039;for the default configuration&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
&lt;br /&gt;
* All 7 &amp;lt;code&amp;gt;fetch()&amp;lt;/code&amp;gt; call sites send page text only to the user-configured LLM server URL (default &amp;lt;code&amp;gt;localhost:11434/1234&amp;lt;/code&amp;gt;). Non-localhost URLs require an explicit per-origin browser permission prompt.&lt;br /&gt;
* No third-party endpoints anywhere; declared Firefox data-collection permission is &amp;quot;none&amp;quot;, consistent with the code.&lt;br /&gt;
* Translations are inserted via &amp;lt;code&amp;gt;textContent&amp;lt;/code&amp;gt; only (no XSS sink); all &amp;lt;code&amp;gt;innerHTML&amp;lt;/code&amp;gt; uses are static template strings.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Conditions (configuration risks, not code defects):&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
# Point it only at localhost or a trusted machine — page text goes to whatever server URL is configured.&lt;br /&gt;
# Remote (LAN) server URLs are plain HTTP — translated page content is cleartext on the wire.&lt;br /&gt;
# Leave the translation cache at its default (&amp;lt;code&amp;gt;off&amp;lt;/code&amp;gt;) for sensitive pages; &amp;lt;code&amp;gt;persistent&amp;lt;/code&amp;gt; mode stores translated page text in IndexedDB.&lt;br /&gt;
# The optional &amp;lt;code&amp;gt;&amp;amp;lt;all_urls&amp;amp;gt;&amp;lt;/code&amp;gt; permission (floating button) runs the content script on every page — broad, but user-initiated, and data still flows only to the configured endpoint.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Caveats:&amp;#039;&amp;#039;&amp;#039; static review only (no runtime network capture); the AMO store artifact was not diffed against the repo; verdict covers commit d2b0907 only — updates require a delta re-review.&lt;br /&gt;
&lt;br /&gt;
== Related ==&lt;br /&gt;
&lt;br /&gt;
* [[Open Source Software Analysis]] — architecture/contribution analysis of OSS projects (complementary, not a security review)&lt;br /&gt;
* [[Procedure: CC-Blast Data Breach Prevention]]&lt;br /&gt;
* [[SCA Program Plan 260320]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Security]]&lt;br /&gt;
[[Category:SOP]]&lt;br /&gt;
[[Category:IT Operations]]&lt;br /&gt;
[[Category:Open Source]]&lt;/div&gt;</summary>
		<author><name>Justinaquino</name></author>
	</entry>
</feed>