T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party Package Installation Creates Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward guide for adding You.com tools to Vercel AI SDK apps, with ordinary integration risks but no evidence of hidden or malicious behavior.
Before installing, review the npm package and lockfile, prefer a pinned version in production, keep the You.com API key in environment variables or a secrets manager, and avoid sending confidential prompts, URLs, or regulated content to the You.com tools unless that data sharing is approved.
SKILL.md:23Unpinned Third-Party Package Installation Creates Supply-Chain Risk
SKILL.md:110API Key Literal Example Encourages Secrets in Source Code
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
* Using standard `YDC_API_KEY`?
* Or custom name? (if custom, get the name)
* Have they set it in their environment?
* If NO: Guide them to get key from https://you.com/platform/api-keys
3. **Ask: Which AI SDK Functions?**
* Do they use `generateText()`?
The skill instructs users to integrate external You.com tools that send prompts and potentially fetched/extracted web content to third-party services, but it does not prominently warn the user about that data flow. This can lead to unintended disclosure of sensitive prompts, URLs, or extracted content when developers use the integration in applications handling confidential data.
No suspicious patterns detected.