T08 · Insecure Dependencies
- Location
references/testing.md:10- Finding
Unpinned Development Dependency Creates Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
npm ci ``` ]]>
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Cloudflare Durable Objects reference, but some best-practice examples could lead an agent to generate insecure public APIs if copied directly.
Review generated Worker code carefully before deployment. Require authentication and object-level authorization for every Durable Object route, derive identity from verified sessions or tokens, restrict CORS to trusted origins, explicitly reject unsupported methods, and pin development dependencies when following the testing setup.
references/testing.md:10Unpinned Development Dependency Creates Supply-Chain Risk
references/workers.md:136Durable Object API Example Omits Authentication and Authorization
references/workers.md:279Wildcard CORS Policy Unnecessarily Exposes API Operations to All Origins
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
async processItem(id: string) {
const item = await this.ctx.storage.get<Item>(`item:${id}`);
if (item?.status === "pending") {
await fetch("https://api.example.com/process"); // Other requests can run here!
await this.ctx.storage.put(`item:${id}`, { status: "completed" });
}
}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
describe("Worker HTTP", () => {
it("should increment via POST", async () => {
const res = await SELF.fetch("http://example.com?id=test", {
method: "POST",
});
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
});
it("should get count via GET", async () => {
await SELF.fetch("http://example.com?id=get-test", { method: "POST" });
await SELF.fetch("http://example.com?id=get-test", { method: "POST" });
const res = await SELF.fetch("http://example.com?id=get-test");
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
});
it("should get count via GET", async () => {
await SELF.fetch("http://example.com?id=get-test", { method: "POST" });
await SELF.fetch("http://example.com?id=get-test", { method: "POST" });
const res = await SELF.fetch("http://example.com?id=get-test");
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
No suspicious patterns detected.