fabric-cli

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/export_semantic_model_as_pbip.py

No strong evidence of intentional malware (no exfiltration, persistence, or secret theft) is present in this fragment; it functions like a model export/generation tool. However, it contains a meaningful supply-chain style integrity risk: decoded TMDL parts are written to filesystem paths derived directly from untrusted remote JSON (`definition.parts[*].path`) with no traversal/containment safeguards. If an attacker can influence the returned model definition, this could enable arbitrary file write/overwrite within the user’s permissions. This warrants code hardening (validate/normalize `part_path`, disallow absolute paths and `..`, and ensure writes remain under the intended output directory).

Confidence: 60%Severity: 68%
Audit Metadata
Analyzed At
Apr 25, 2026, 01:36 AM
Package URL
pkg:socket/skills-sh/data-goblin%2Fpower-bi-agentic-development%2Ffabric-cli%2F@1a96a3b18c394e250d9fc179ff8707978a131a5f