T08 · Insecure Dependencies
- Location
scripts/json_tool.py:121- Finding
Unpinned Third-Party Dependency Installation Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple local JSON utility, but users should know some operations overwrite or create files unless an output path is used.
Install only if you are comfortable with a local script reading and writing JSON files you point it at. For important data, pass --output or keep a backup because some operations modify the original file by default.
scripts/json_tool.py:121Unpinned Third-Party Dependency Installation Guidance
The skill documentation advertises running a local Python script that can format, minify, convert, and sort JSON, and the static analyzer detected file-write capability, but the manifest declares no explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: consumers of the skill cannot tell up front that it may modify or create files, especially during conversions or formatting operations that commonly write output. In this context the capability is plausibly legitimate, but undeclared write access still increases risk if the implementation writes unexpected paths or overwrites user data.
The tool defaults to writing formatted, minified, or sorted JSON back to the original input file when no --output path is supplied. This creates an unsafe destructive side effect: a user or calling agent expecting a read-only transformation can unintentionally overwrite source data, potentially causing data loss or corruption of important configuration files.
The conversion paths create .yaml or .csv files on disk, but the skill only states it can 'transform JSON data' and does not disclose that conversion produces new files. This is a file-writing side effect that lacks an upfront user warning in the code's visible descriptions or CLI help.
No suspicious patterns detected.