T08 · Insecure Dependencies
- Location
package.json:19- Finding
Unused Mutable Dependency Introduces Avoidable Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly aimed at automating TikTok replies, but it handles account credentials and promised dry-run behavior too loosely for public posting automation.
Review before installing. Use a dedicated low-privilege TikTok app or test account, avoid storing real tokens in the project directory, add config.json to .gitignore, and do not rely on dryRun as a safety control unless the code is fixed to enforce it. Treat watch mode as live automation and monitor account activity closely.
package.json:19Unused Mutable Dependency Introduces Avoidable Supply-Chain Exposure
SKILL.md:35TikTok API Credentials Are Stored in a Plaintext Project Configuration File
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README forces a single language/locale experience for all users through its natural-language instructions and warnings. Under the stated policy, this is a violation unless the skill offers language choice or clearly documents a justified region-specific limitation, which is not present here.
The skill name, warnings, setup, usage instructions, and disclaimer are all written in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The config specifies Chinese keywords and Chinese reply templates, which implies the skill is constrained to a specific language/locale. There is no accompanying natural-language indication that the user can choose the language or that the locale restriction is intentional and documented.
The file’s user-facing description and operational messages are entirely in Chinese, beginning with a Chinese-only skill title. Under the policy, language restrictions should offer user opt-in or be clearly documented as region-specific; this file provides neither.
The program advertises dryRun=true as a mode that will not actually send replies, but the control flow does not enforce that guarantee before invoking replyComment. In a real implementation where replyComment performs live API calls, operators may unintentionally automate account actions despite believing they are in safe test mode, causing unauthorized posting, rate-limit issues, or account sanctions.
The description and display name are written only in Chinese ("TikTok 热门视频自动回复技能" / "TikTok 自动回复"), which imposes a specific language in user-facing metadata without offering an alternative or opt-in. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.
The dependency uses a semver range (^2.6.9) rather than an exact pinned version, which can lead to non-reproducible installs and unexpected adoption of changed transitive code. In a skill context that may process social-media data or perform automated actions, this weakens supply-chain control and makes dependency risk harder to assess.
"node": ">=18.0.0"
},
"dependencies": {
"node-fetch": "^2.6.9"
},
"clawhub": {
"slug": "tiktok-auto-reply",
The manifest references node-fetch with a non-exact version while known advisories exist in the 2.x line, so the actual installed package may be vulnerable depending on resolution. Even though package.json alone does not prove exploitation, leaving an advisory-affected dependency range unresolved creates avoidable supply-chain and runtime risk.
No suspicious patterns detected.