T08 · Insecure Dependencies
- Location
README.md:7- Finding
Unpinned executable installation chain
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-aligned for querying China Railway 12306, with disclosed network use and local output files, but it has install and HTML-report hardening issues.
Reasonable to install if you are comfortable with a Node-based skill contacting 12306 and storing station cache/report files locally. Prefer pinned installation sources when available, use Markdown or JSON output for lower-risk display, and treat generated HTML reports as local files containing your travel query details.
README.md:7Unpinned executable installation chain
scripts/query.mjs:181Remote API fields are incompletely escaped in generated HTML
The README instructs users to install and run a remote skill via npx skills add kirorab/12306-skill without pinning a specific immutable version. That creates a supply-chain risk: future upstream changes, account compromise, or a malicious republish could cause users to fetch different code than expected.
The skill invokes Node.js scripts that query the official 12306 API, which implies network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a mismatch between the documented contract and the actual capability, making review, sandboxing, and policy enforcement weaker and increasing the chance of unintended outbound requests.
This is a markdown file, so SQP-2 applies to omissions in user-facing safety disclosures. The README states that the skill directly calls the 12306 official API, but it does not warn users that origin, destination, date, and related query parameters will be sent over the network to a third-party service.
The skill defaults to HTML mode that writes query results to disk, but this side effect is not clearly surfaced as a warning near the primary usage. Hidden file writes can surprise users and agents, potentially leaving travel-related data on disk or causing downstream components to treat the behavior as read-only when it is not.
The generated HTML sets lang="zh-CN" and uses Chinese-only labels and toLocaleString('zh-CN', { timeZone: 'Asia/Shanghai' }), which forces a specific language/locale in user-facing output. The file does not offer any language selection or document that the tool is intentionally limited to a Chinese-speaking audience as a justified region-specific constraint.
The station resolution logic strips Chinese suffixes like “市” and “站”, and the script is tied to 12306 Chinese station data, indicating a Chinese-locale assumption. There is no natural-language indication or user opt-in for this locale constraint, so the skill implicitly forces a specific language/locale behavior.
No suspicious patterns detected.