T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Python and Node.js Profiling Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent performance-profiling reference, but it includes disruptive database and load-testing commands without enough safety scoping.
Install only if you are comfortable reviewing commands before execution. Use these examples only on systems and services you own or are authorized to test, avoid production unless approved, preserve diagnostic logs before clearing them, and prefer pinned, locally installed profiling tools over global or latest-version installs.
SKILL.md:16Unpinned Python and Node.js Profiling Dependencies
references/load-test.md:40Mutable Go Tool Installation Using the Latest Version
references/system.md:57Execution of Scripts from a Mutable Git Repository
Referenced artifact was not completely inspected
- **Node.js 分析**: [references/nodejs.md](references/nodejs.md) - V8 分析, clinic.js
The manifest description and primary content are written in Chinese, and the file does not indicate that the skill is region-specific or provide any language opt-in. This creates a natural-language policy concern because it implicitly constrains users to a specific language without documented justification.
The documentation includes PostgreSQL query-cancellation and termination commands without any warning about operational risk or guidance on safe use. In a performance-profiling skill, users may copy these commands into production, causing disruption to legitimate workloads, aborted transactions, or application instability.
The Redis section includes SLOWLOG RESET without noting that it permanently clears diagnostic history. In a troubleshooting guide, this can lead users to erase evidence needed for root-cause analysis or incident response, especially if run prematurely on a live system.
The document provides ready-to-run load-testing commands that can generate significant HTTP traffic, including concurrent requests and scripted POST bodies, but it does not warn users to obtain authorization or avoid running them against third-party production systems. In a skill intended as a performance-profiling reference, this omission increases the chance of misuse for accidental denial-of-service or unauthorized stress testing.
The file's headings, comments, and instructional text are all in Chinese, with no indication that the skill is region-specific or that users may opt into another language. This can violate language/locale policy when a skill implicitly forces a language without user choice or justification.
The document title and all instructional content are written exclusively in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This is a natural-language locale constraint and may violate organizational language-choice policy when presented as a general reference skill.
The file title and all instructional content are presented in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This is a natural-language locale constraint that can violate organizational language-choice policy when not documented or optional.
This markdown file presents all instructions and labels in Chinese only, which can impose a specific language on users without offering a choice. The policy explicitly calls for flagging language or locale constraints when they are forced without user opt-in or justification.
No suspicious patterns detected.