T08 · Insecure Dependencies
- Location
SKILL.md:59- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a small local ASCII-art helper whose behavior matches its stated purpose, with only minor documentation and dependency-installation cautions.
Install pyfiglet only from a trusted environment, preferably pinned in a virtual environment. Expect the skill's docs and CLI output to be in Chinese, and note that the website links in the README are promotional rather than required for the tool to run.
SKILL.md:59Unpinned Third-Party Dependency Installation
The skill metadata and all user-facing documentation are written in Chinese, including the title, feature list, usage notes, and cautions. This creates a language/locale constraint without any opt-in, alternative language option, or explanation that the skill is intended only for a Chinese-speaking audience.
This code file contains natural-language descriptions, help text, and usage output entirely in Chinese, including the module docstring and CLI argument/help strings. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which it is not here.
No suspicious patterns detected.