T08 · Insecure Dependencies
- Location
SKILL.md:36- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but one optional link-resolution path can make requests to unvalidated URLs from search results, which is risky on private networks.
Install only if you are comfortable running a web-scraping tool that contacts Sogou and WeChat. Use it in a restricted network environment, avoid --ua-rotate unless you have a legitimate compatibility reason, and avoid --resolve-url or --fetch-content until URL allowlisting is added. Prefer pinned dependency versions in an isolated virtual environment.
SKILL.md:36Unpinned Third-Party Dependencies Create Supply-Chain Risk
search.py:135Insufficient URL Validation Permits Blind Server-Side Request Forgery
The skill advertises and documents network access and optional file output, but it does not declare any explicit tool scope or permissions boundary. That creates a least-privilege gap: an agent or runtime may invoke a networked, file-writing skill without clear user-visible authorization constraints, increasing the chance of unintended external requests or writes.
The invocation description is broad enough that an agent could route loosely related requests about WeChat articles or public-account content into this skill without confirming user intent. Because the skill performs live web requests and can optionally do further fetching, overbroad triggering can cause unnecessary data egress, unexpected scraping activity, or actions the user did not specifically request.
The file mandates a strict output template using Chinese field labels such as '标题' and '摘要' and says results 'must' follow that format. This imposes a specific language/locale on responses without offering the user a language choice or documenting that the skill is intentionally Chinese-only.
Built-in User-Agent rotation is a common anti-detection/anti-rate-limit evasion technique and is not necessary for ordinary article search functionality. In this context it increases suspicion because it can help sustain scraping against target defenses and masks client identity across repeated requests.
The skill is described as returning article search metadata, but the implementation can also fetch and return full article body text via the fetch_content path. This expands the data-access scope beyond the declared purpose, creating a capability mismatch that can surprise users, operators, or policy controls and may enable unauthorized content collection at scale.
This file contains user-facing natural-language descriptions and command-line help text exclusively in Chinese. Under the policy, forcing a specific language without opt-in or an explicit region-specific justification is a natural-language policy violation.
The code optionally resolves intermediary Sogou links into direct WeChat article URLs, which exceeds a simple 'return links from search results' description. While not inherently malicious, this bypasses an indirection layer and changes the nature of what destinations are exposed and subsequently fetched.
No suspicious patterns detected.