T08 · Insecure Dependencies
- Location
SKILL.md:50- Finding
Uncontrolled Installation of Mutable Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent admin UI prototyping skill; its main risk is disclosed project scaffolding that may install JavaScript dependencies.
Install only if you want a Chinese-locale Vue 3 + Arco admin prototype helper that may modify files under webui/admin-ui and run pnpm install during scaffolding. Review generated delete/upload/API examples before connecting them to real backends, and consider pinning dependencies or using a reviewed lockfile for stricter supply-chain control.
SKILL.md:50Uncontrolled Installation of Mutable Third-Party Dependencies
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
<a-popconfirm position="top" content="确认永久删除?" @ok="onDelete(record)">
<a-button type="text" status="danger" size="small">
<icon-delete />
</a-button>
</a-popconfirm>
The skill directs the agent to create or modify files in webui/admin-ui and to run pnpm install without requiring explicit user confirmation or warning that the workspace will be changed. This creates a real safety issue because dependency installation executes package-manager lifecycle scripts and file writes can alter the repository state unexpectedly, which is especially risky in an agentic context where users may have asked only for advice or a draft.
Defaulting all UI copy to Chinese without user opt-in is a policy and usability risk because it can cause the agent to generate outputs in an unexpected language, potentially violating user requirements or organizational language expectations. In this skill's context the issue is less about system compromise and more about producing inappropriate or noncompliant content by default.
The skill enables implicit invocation with no visible trigger constraints or narrowing conditions, so the agent may activate this skill in situations broader than intended. Because the skill can scaffold files and update a preview project, overbroad activation increases the chance of unintended code generation or project modifications in the wrong context.
This markdown file includes examples for dangerous operations such as 删除 and 重置, but it does not warn users to add confirmation prompts or explain that these actions may be destructive. For markdown files, safety-relevant behaviors that could affect user data or system integrity should include explicit warnings in the skill description.
The table action column includes a 删除 button as a standard action example, but the markdown provides no caution that deletion is destructive or should be confirmed. This omission can normalize unsafe implementation of irreversible actions in downstream usage.
This markdown file documents a custom upload flow and shows code that sends user-selected files via uploadFile(fileItem.file), but it does not include any warning about data being transmitted off the client. For markdown files, omission of warnings about behaviors affecting user data or privacy is in scope.
The document is written entirely in Chinese and explicitly defines placeholders such as '页面中文名称', while the generated HTML template hard-codes lang="zh-CN". This indicates a fixed language/locale expectation without any stated user opt-in or justification that the skill is intended only for a China-specific context.
This markdown file contains user-facing documentation exclusively in Chinese, including the title, descriptions, and props table. Under the policy rule for language/locale, forcing a single language without opt-in or justification can be a natural-language policy violation.
This markdown file uses only Chinese for the title, description, examples, and property explanations. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue when no alternative language option or scope justification is provided.
This markdown file includes a page template with record deletion and an irreversible-action message, but the surrounding skill documentation does not explicitly warn that generated templates may include destructive operations affecting user data. For markdown files, omissions of warnings about behaviors that could affect user data or system integrity should be flagged.
The scaffolded index.html sets <html lang="zh-CN">, which enforces a specific locale in generated output. Because the file does not offer an alternative or state that the scaffold is region-specific, this is a natural-language locale policy concern.
No suspicious patterns detected.