T08 · Insecure Dependencies
- Location
SKILL.md:39- Finding
Unverified Third-Party Code Is Copied into an Executable Project
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a PyOmniTS documentation helper, but it also directs agents to clone outside research code and copy or rewrite it into a local PyOmniTS installation without enough safety controls.
Install only if you are comfortable treating this as an active code-adaptation helper, not just documentation. Before following its replication workflow, use a trusted repository, pin a reviewed commit, inspect copied files and dependencies, work in a branch or disposable environment, back up the PyOmniTS installation, and confirm every file write before applying changes.
SKILL.md:39Unverified Third-Party Code Is Copied into an Executable Project
The skill claims to provide documentation-oriented help, but later includes operational workflows that direct code import and project modification. This mismatch is dangerous because it can mislead users or higher-level agents into trusting the skill as low-risk reference material when it actually contains instructions that change local code and integrate external repositories.
The skill is presented as a documentation/helper skill, but it instructs the agent to perform repository cloning and direct file copying/rewriting into a local PyOmniTS installation. That expands the skill from informational guidance into making code and filesystem changes, which can import unreviewed third-party code and alter the user's environment without adequate safety boundaries.
The instructions tell the agent to copy or rewrite files inside ${PYOMNITS_PATH} without warning that these actions modify the user's local installation and may overwrite existing work. In this context, the lack of cautions, backups, or confirmation requirements increases the chance of unsafe changes, data loss, and integration of untrusted code into an execution environment.
No suspicious patterns detected.