T08 · Insecure Dependencies
- Location
SKILL.md:3- Finding
Unpinned Playwright Installation Creates Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly coherent for Taobao image search, but it stores reusable login sessions and can automatically add items to a live shopping cart without a strong confirmation gate.
Review this before installing if you use a real Taobao account. Use it only on a trusted personal machine, treat verification-artifacts/taobao-storage-state.json and .pw-user-data-taobao/ as account credentials, delete them when finished, and avoid running the full script unless you explicitly want it to add a selected item to your cart. Pin Playwright and use a lockfile before using this in a sensitive environment.
SKILL.md:3Unpinned Playwright Installation Creates Supply-Chain Exposure
auto-login-taobao.js:89Reusable Taobao Session Credentials Are Persisted Without Permission Hardening
The header comment frames the file as a 'local verification runner', but the implementation logs into Taobao, uploads an image, selects a product, and performs a real '加入购物车' action. This mismatch is dangerous because users or downstream agents may treat it as non-destructive verification while it actually changes account state on a live third-party service.
The README instructs users to run npx playwright without pinning a specific package version, which can cause installation or execution of whatever version is current at runtime. In a skill that automates login and explicitly stores active Taobao session cookies locally, an unpinned toolchain increases supply-chain risk because a compromised or breaking upstream release could execute code in the same environment that handles live browser sessions.
The README instructs users to run npx playwright without pinning a specific version, which can fetch and execute whatever package version is current at install time. This creates a supply-chain risk: a compromised upstream release or unexpected breaking change could result in execution of unreviewed code on the user's machine.
The install step uses npx playwright without pinning an exact version, so execution depends on whatever package version is currently resolved from the registry at runtime. This creates a supply-chain risk: a malicious or compromised newly published version, or an unexpected breaking update, could run arbitrary install-time code or alter browser automation behavior on the user's machine.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The script saves Taobao browser storage state to a local JSON file after login, which can include cookies and session tokens that allow account reuse without re-authentication. Although it prompts the user to log in, it does not clearly disclose before collection that persistent authentication material will be written to disk and retained in a predictable location, increasing the chance of credential leakage from local compromise, backup systems, or accidental sharing.
The script performs a real add-to-cart operation automatically once a logged-in session is present, with no interactive confirmation, safeguard flag, or final prompt. In an agent-skill context, this is more dangerous because it can silently mutate a user's e-commerce account and trigger unintended cart pollution or follow-on purchasing workflows.
This markdown file is entirely written in Chinese and does not indicate that other language options are available. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.
The browser context is hard-coded to use zh-CN, and the script's user-facing messages are also in Chinese. This imposes a specific language/locale without opt-in, which matches the language-policy violation criteria for natural-language policy concerns.
This JavaScript file contains multiple user-facing console messages exclusively in Chinese, such as error, status, and login instructions. The file provides no indication that the user can choose a language or that the Chinese-only locale is an intentional, documented constraint, which creates a natural-language policy concern.
The script hardcodes locale: 'zh-CN' when creating the browser context, which enforces a specific locale regardless of user preference. This is a natural-language policy concern because the file does not offer an opt-in or explain why the locale restriction is required.
No suspicious patterns detected.