T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:52- Finding
Mutable Third-Party JavaScript Is Retrieved and Executed Without Integrity Verification
- Content
View full analysis
``` The reference files repeat the same unsafe dependency-loading pattern, including: ```html ``` ```html ...[truncated 3425 chars]- Remediation
View remediation
``` 3. Prefer vendoring reviewed dependency artifacts with the application so that opening it does not retrieve mutable executable code. 4. If remote hosting is required, serve approved artifacts from a controlled, immutable location and monitor them for unauthorized changes. 5. Add a restrictive Content Security Policy that permits scripts only from approved sources and limits outbound connections to required endpoints. 6. Restrict `connect-src` to the Proton proxy and explicitly approved services. Avoid broad wildcards. 7. Review dependency provenance, release signatures, vulnerability advisories, and transitive dependencies before updating pinned versions. 8. Update `SKILL.md`, `references/PROTON_DRIVER.md`, and `references/VISTRAL_API.md` consistently so generated applications cannot reintroduce the unsafe pattern from a reference example. 9. Ensure the Proton proxy requires appropriate authentication and authorization and enforces restrictive CORS behavior to reduce the impact of compromised browser code. ]]>
