T03 · Remote Payload Retrieval and Execution
- Location
assets/html-starter-template.html:8- Finding
Unpinned Third-Party JavaScript Is Retrieved and Executed at Runtime
- Content
View full analysis
``` ### Technical Analysis The starter template loads Chart.js and MathJax directly from jsDelivr. Chart.js is not pinned to any version, while MathJax is constrained only to major version 3. Neither resource includes Subresource Integrity metadata. When a generated page is opened, the browser retrieves and executes the current resources returned by the CDN. The effective executable code can therefore change after the Skill package has been audited. A compromised package release, package account, CDN, or dependency-resolution path could inject arbitrary JavaScript into every page based on this template. Chart and mathematical rendering are legitimate requirements of the Skill. However, executing mutable remote code is not the minimum privilege necessary to provide those features; audited local copies or integrity-pinned resources can provide the same functionality with less supply-chain exposure. ### Attack Path 1. An attacker compromises a relevant package publication account, CDN delivery path, or mutable dependency resolution. 2. The attacker causes one of the referenced URLs to return modified JavaScript. 3. A user opens an educational HTML page generated from the starter template while network access is available. 4. The browser downloads and executes the modified script in the page context. 5. The malicious script can read or alter page content, capture datasets ...[truncated 771 chars]- Remediation
View remediation
``` 3. Prefer vendoring verified copies of Chart.js and MathJax into the Skill package when producing self-contained pages. 4. Record dependency versions and SHA-256 hashes in project documentation. 5. Add a restrictive Content Security Policy that permits scripts only from explicitly approved sources and blocks unexpected network connections. 6. Recalculate integrity hashes only after reviewing intentional dependency upgrades. 7. Provide an offline template variant that does not require runtime network access. ]]>
