T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Node.js Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Deutsche Bahn helper, but it automatically stores travel itinerary data locally and ships a dated itinerary in the package.
Review before installing. This skill appears intended for German rail workflows and does not show credential theft, backdoors, or destructive behavior, but expect it to contact DB-related services and to retain parsed travel plans locally unless changed. Remove bundled or generated active.json files you do not want kept, and prefer pinned dependencies for reproducible installs.
SKILL.md:10Unpinned Node.js Dependencies Create Supply-Chain Risk
scripts/lib/helpers.mjs:131Plaintext Itineraries Are Automatically Written to a Predictable Path
scripts/connections/active.json:1Packaged Artifact Contains a Dated Travel Itinerary
YARA rule matched a known webshell pattern (PHP, Python, JSP, or ASPX webshell).
ebundene Einstiegshilfe',
'84': 'Zug verkehrt richtig gereiht',
'85': 'Ein Wagen fehlt',
'86': 'Gesamter Zug ohne Reservierung',
'87': 'Einzelne Wagen ohne Reservierung',
'88': 'Keine Qualitätsmängel',
'89': 'Reservierungen sind wieder vorhanden',
'90': 'Kein gastronomisches Angebot',
'91': 'Fahrradmitnahme nicht möglich',
'92': 'Eingeschränkte Fahrradbeförderung',
'93': 'Behindertengerechte Einrichtung fehlt',
'94': 'Ersatzbewirtschaftung',
'95': 'Universal-WC fehlt',
'96': 'Überbesetzung mit Kulanzleistungen',
'97': 'Überbesetzung ohne Kulanzleistungen',
'98': 'Sonstige Qualitätsmängel',
'99': 'Verzögerungen im Betriebsablauf',
'900': 'Anschlussbus wartet(?)',
'1000': 'Kundentext',
'1001': 'Keine Zusatzhinweise',
'2000': 'Interner Text',
};
export function lookup(code) {
return messages[String(code)] ?? `Unbekannte Ursache (code ${code})`;
}
When the input is treated as plaintext, the function parses it and unconditionally persists the resulting connection data to a local file. There is no confirmation prompt, logging, or inline comment/docstring warning the user that supplying plaintext causes a file write side effect.
todayDateStr() forces the 'sv-SE' locale and 'Europe/Berlin' time zone for date formatting. This is a natural-language/locale policy concern because it imposes a specific regional formatting choice without any opt-in or documented justification in this file.
This file defines a large set of user-facing status messages exclusively in German, with no indication that language selection is optional or region-scoped. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.
No suspicious patterns detected.