T08 · Insecure Dependencies
- Location
SKILL.md:1004- Finding
Unpinned Remote Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a frontend design guidance file; its risky parts are normal but review-worthy package and asset-source guidance, not hidden or malicious behavior.
Install only if you are comfortable with a skill that may guide the agent to add frontend dependencies, run design-system scaffolding commands, and use external image or logo sources. Pin package versions where possible, approve dependency installs explicitly, and review generated project changes before committing or deploying.
SKILL.md:1004Unpinned Remote Package Execution Through npx
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
* `https://picsum.photos/seed/{descriptive-seed}/{w}/{h}` for placeholder photography (seed should describe the section, e.g. `marrow-cookware-kitchen`)
* Actual stock or brand URLs when the brief provides them
* Open-license sources (Unsplash via direct URL, Pexels) if explicitly allowed
3. **Last resort: tell the user.** If neither is possible, do NOT fill the page with hand-rolled SVG illustrations or div-based "fake screenshots." Instead, leave clearly-labeled placeholder slots (`<!-- TODO: hero product photo, 1600x1200 -->`) and at the end of the response say: *"This page needs real images at: \[list of placements\]. Please generate or provide them."*
**Even minimalist sites need real images.** A pure-text page is not minimalism. It is incomplete work. Even an editorial Linear-style site needs at least 2-3 real images (hero, one product/lifestyle shot, one supporting image). Generate B&W minimalist photography if the brief is restrained; do not skip images entirely because the dial is low.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
* **`MOTION_INTENSITY: 6`** - 1 = Static, 10 = Cinematic / Physics
* **`VISUAL_DENSITY: 4`** - 1 = Art Gallery / Airy, 10 = Cockpit / Packed Data
**Baseline:** `8 / 6 / 4`. Use these unless the design read overrides them. Do not ask the user to edit this file - overrides happen conversationally.
### 1.A Dial Inference (design read → dial values)
| Signal | VARIANCE | MOTION | DENSITY |
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
This markdown instruction imposes a specific locale/theme preference by requiring both modes and defaulting to system preference for all consumer-facing pages. Under the policy, forcing a presentation preference without explicit user choice or a clearly justified constraint is a natural-language policy violation.
The skill includes instructions to install packages and run scaffolding commands, which broadens it from content generation into environment modification. In an autonomous agent context, this can lead to unreviewed dependency installation, project mutation, and supply-chain exposure if the agent executes commands based on the skill without user confirmation.
The skill pushes the agent toward fetching remote assets from external image sources and logo CDNs as part of normal operation. In an agent setting, this expands data flow to third parties, can leak contextual information through URL construction or requests, and may introduce unreviewed external content into generated pages without explicit user approval.
No suspicious patterns detected.