Jump to content

SOP: Third-Party Software Security Review

From MediawikiCIT
Revision as of 06:23, 9 August 2026 by Justinaquino (talk | contribs) (Create SOP: third-party software security review workflow + first due-diligence result (offline-browser-translate))
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

SOP: Third-Party Software Security Review (Due Diligence)

Purpose: No third-party code — GitHub repos, browser extensions, open-source tools — is installed or run on Comfac machines without a security review first. The review emphasis is data leakage / exfiltration risk, then permissions vs. purpose, obfuscation, supply chain, and repository history.

The full workflow, criteria, and triage script live in the IT-knowledge repo: IT-knowledge/skills/repo-security-review/ (git.gi7b.org). Finished review reports are filed in IT-knowledge/skills/repo-security-review/reports/.

Workflow

  1. Acquire and pin. Clone full history into a scratch area (never a synced project folder). Record the exact commit (git rev-parse HEAD) — the verdict covers that commit only.
  2. Automated triage. Run the pattern pack:
    bash IT-knowledge/skills/repo-security-review/scripts/triage-scan.sh <git-url> agent260222/repo-scans
    
    It scans for hardcoded endpoints, network calls, telemetry keywords, obfuscation/dynamic exec, remote code loading, dangerous extension APIs, data-at-rest, injection sinks, IPC/message surfaces, committed secrets, install/CI hooks, binaries, and contributor history. A clean triage is not a verdict — it finds where to look.
  3. Manual review. Read every triage hit in context; read the manifest/permissions and trace the data flow: what user data is read, where does every network call send, what persists. Every egress destination must be user-configured or justified by the feature — anything else is a finding.
  4. Verdict and report. File the report under reports/YYMMDD-<repo>.md with target + commit, verdict, data-flow map, findings table (with file:line evidence), and caveats.
  5. Re-review on change. A verdict expires on update, permission/manifest change, ownership change, or a dependency adding a binary blob. Diff from the reviewed commit and re-triage the delta.

Criteria Checklist

# Question Fail closed when
1 Can you enumerate every network destination? Hidden/encoded endpoints
2 Does every egress match the stated purpose? Data leaves to a party the user didn't configure
3 Is the permission set minimal for the purpose? Broad grants (<all_urls>, filesystem, exec) without justification
4 Is all executed code readable? Obfuscation, blobs without source, remote code loading
5 Does anything run before you consent? postinstall hooks, curl|sh installs, unpinned self-update
6 What user data is read and where is it stored? Silent persistence of content/credentials
7 Are IPC/message boundaries validated? Privileged handlers trusting unverified senders
8 Is the supply chain pinned? Unpinned deps, unsigned release binaries
9 Does history/metadata support trust? New owner + permission bump, throwaway account
10 Would you notice if an update turned evil? Auto-update with no hash check

Verdicts

  • CLEAN — install OK.
  • CLEAN WITH CONDITIONS — install OK if the listed configuration conditions are met.
  • SUSPICIOUS — do not install; the report lists what would change the verdict.
  • MALICIOUS — do not install; consider reporting upstream.

Severity: Critical (exfiltration, RCE, credential theft) · High (exfiltration capability gated only by config/obscurity, obfuscated payload) · Medium (over-broad permissions, cleartext transport of user content, missing origin checks) · Low (privacy footguns, hygiene) · Info.

Review Log

Date Target Commit Verdict Report
2026-08-09 offline-browser-translate (Firefox extension, local-LLM page translation) d2b0907 CLEAN WITH CONDITIONS IT-knowledge: skills/repo-security-review/reports/260809-offline-browser-translate.md

2026-08-09 — offline-browser-translate (Local LLM Translator)

Static review of all source (60 commits, full history) at commit d2b0907. No exfiltration, no telemetry, no obfuscation, no remote code loading, no dependencies or install hooks. The extension's "your data never leaves your machine" claim is accurate for the default configuration:

  • All 7 fetch() call sites send page text only to the user-configured LLM server URL (default localhost:11434/1234). Non-localhost URLs require an explicit per-origin browser permission prompt.
  • No third-party endpoints anywhere; declared Firefox data-collection permission is "none", consistent with the code.
  • Translations are inserted via textContent only (no XSS sink); all innerHTML uses are static template strings.

Conditions (configuration risks, not code defects):

  1. Point it only at localhost or a trusted machine — page text goes to whatever server URL is configured.
  2. Remote (LAN) server URLs are plain HTTP — translated page content is cleartext on the wire.
  3. Leave the translation cache at its default (off) for sensitive pages; persistent mode stores translated page text in IndexedDB.
  4. The optional <all_urls> permission (floating button) runs the content script on every page — broad, but user-initiated, and data still flows only to the configured endpoint.

Caveats: static review only (no runtime network capture); the AMO store artifact was not diffed against the repo; verdict covers commit d2b0907 only — updates require a delta re-review.