T08 · Insecure Dependencies
- Location
SKILL.md:253- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent KDP book-production helper, with expected but notable use of Google AI APIs, local output files, KDP upload guidance, and paid ads guidance.
Install in a virtual environment, pin dependencies where possible, prefer an environment variable or secret manager over passing API keys on the command line, and review every KDP submission, pricing choice, AI disclosure, and Amazon Ads campaign before allowing an agent to upload, submit, or launch anything that affects your Amazon account or ad spend.
SKILL.md:253Unpinned Third-Party Dependencies Create a Supply-Chain Risk
scripts/validate-book.py:571Validator Loads API Credentials Unnecessarily and Supports Secrets in Process Arguments
While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.
While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.
While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
document.querySelector('input[type=file]').dispatchEvent(new Event('change', {bubbles:true}));
- Wait for `#data-print-book-interior-processing-status` to show COMPLETED before proceeding
- Reload KDP page before each upload session — stale form state causes silent failures
**Category selection:**
- Use the cascade-select dropdowns in the category modal
The skill references local scripts, environment variables, credential files, and file-producing workflows, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this can lead to overbroad access assumptions and unsafe execution of file write or env-reading actions beyond what the user intended.
Overly broad triggers can cause the skill to activate for generic book-creation or publishing requests, leading an agent to load instructions involving script execution, credential usage, file generation, or browser automation when the user did not ask for that level of action. In agent systems, unintended invocation increases the chance of overreach and misuse of powerful capabilities.
The manifest and top-level description frame this skill as helping create, format, and publish children's and activity books to Amazon KDP, including story generation, PDF assembly, covers, metadata, and upload guidance. The dedicated 'Amazon Ads Quick-Start' section adds marketing/advertising campaign management capabilities that are not justified by that stated publishing-focused purpose.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
5. **No text in AI illustrations**: Every image prompt must include "no text, no words, no letters". Text baked into AI images is often garbled. Always overlay text programmatically.
6. **Descriptions from finished content**: Never write the description from the original prompt. Write it after the story is final — use actual character names and plot.
7. **KDP categories**: Select via cascade dropdowns in the modal, then JS-click the placement checkbox. Don't rely on Playwright click for the final checkbox.
The script transmits user-provided prompts and derived scene descriptions to external Google AI services for text and image generation, but gives no explicit notice or consent flow before sending potentially sensitive content off-host. In an agent-skill context, prompts may contain proprietary, personal, or unpublished manuscript data, so silent exfiltration to a third party creates a real privacy and data-handling risk.
When --check-text-in-images is used, the script transmits local image contents to Gemini Vision, but the messaging does not clearly and prominently warn that files are being sent to an external third-party service. In a publishing workflow, these images may be unpublished or sensitive commercial content, so undisclosed exfiltration to a remote API is a real privacy and confidentiality risk.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
{
"inline_data": {
"mime_type": "image/png",
"data": __import__("base64").b64encode(img_data).decode(),
}
},
{
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
pages = convert_from_path(str(pdf_path), dpi=72, first_page=1, last_page=10)
blank_pages = []
for i, page_img in enumerate(pages):
arr = __import__("numpy").array(page_img.convert("L"))
if arr.std() < 3.0: # Near-zero variance = blank white page
blank_pages.append(i + 1)
The validator silently loads a Google AI API key from a user-specific credential file outside the declared command-line inputs. That expands the tool's access scope unexpectedly and can cause downstream network actions to occur with ambient credentials the user did not explicitly provide, violating least surprise and least privilege.
This markdown file gives step-by-step instructions to create and launch a paid advertising campaign, including a no-end-date setting and daily budget, but it does not explicitly warn users that this will incur real charges. Because the guidance could affect user finances, a user-facing warning about paid spend and monitoring costs is appropriate.
This function accesses sensitive credentials from GOOGLE_AI_API_KEY or ~/.clawdbot/credentials/google_ai.json. There is no user-facing disclosure beyond operational setup text, so the skill lacks a clear warning that it will read secrets from the environment or filesystem.
Accessing a sensitive credential file in a hidden user directory without clear disclosure is a transparency and trust-boundary issue. Even if the key is only used for the validator's stated image-check feature, undeclared credential harvesting behavior is risky in an agent skill because users may not expect local secret material to be read automatically.