Security checks for vulnerabilities and agentic risk
Overview
The skill is a coherent React template, but it should be reviewed before installation because it includes scanner-reported vulnerable npm development dependencies.
Review and update the npm dependencies before installing or running this template, especially Vite/PostCSS-related tooling. Keep the dev server local, avoid building untrusted project inputs, and treat the Chinese-only UI as an intentional template constraint that may need localization for other users.
Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (38)
Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)
High
Category
Supply Chain
Confidence
95% confidence
Finding
browserslist 4.28.1 is present and the cited advisories include prototype write and unbounded memory growth conditions when handling untrusted browserslist-stats or adversarial query patterns. Although this dependency is used in build tooling rather than app runtime, it can still materially affect CI/dev systems by crashing jobs, exhausting memory, or corrupting object state if fed attacker-controlled configuration or stats files.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)
High
Category
Supply Chain
Confidence
88% confidence
Finding
nanoid 3.3.11 is present through PostCSS, and the advisories describe denial-of-service style failure modes such as infinite loops or integer overflow in edge-case generator usage. The finding is valid at the dependency level, though exploitability in this template is indirect and mostly constrained to build-time tooling paths that invoke the vulnerable code with attacker-controlled parameters.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: postcss==8.5.8 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more
High
Category
Supply Chain
Confidence
95% confidence
Finding
postcss 8.5.8 is included via Vite and has multiple advisories, including arbitrary file read via source map handling and XSS in generated CSS output. In the context of a frontend template, PostCSS is a build-time component, so the issue is real and potentially serious for CI/developer environments or systems that process untrusted CSS/content, though not necessarily immediately exploitable in a default local-only workflow.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: vite==5.4.21 — 3 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-53632 (launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows)
High
Category
Supply Chain
Confidence
97% confidence
Finding
vite 5.4.21 is a core dev dependency for this template, and the cited advisories include path traversal in optimized dependency .map handling, Windows path-deny bypass, and NTLM hash disclosure via launch-editor UNC path handling. These are real and more relevant than many other findings because Vite is directly used by developers running and building the template, making dev workstations and CI runners plausible targets if exposed to malicious requests or crafted project inputs.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: vite==5.4.21 — 3 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-53632 (launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows)
High
Category
Supply Chain
Confidence
96% confidence
Finding
The resolved vite version is flagged with multiple advisories, including path traversal and Windows-specific filesystem/UNC handling issues. Because this project is a template intended for development use, vulnerable build tooling is especially relevant: developers commonly run Vite locally or in shared environments, increasing the chance of exposure during development, preview, or CI workflows.
Content
No source excerpt is available for this finding.
Undeclared Tool Scope
Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding
The specification hard-codes Chinese labels such as "首页" as the default first menu item and repeats that requirement in navigation rules. This imposes a specific locale in the skill's natural-language guidance without any opt-in, alternative locale handling, or justification that the skill is strictly region-specific.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding
This bundled JS hard-codes a full Simplified Chinese locale object and passes it into the top-level configuration, which makes the skill/app operate in a specific language by default. The file does not show any user-selectable locale setting, opt-in, or documented justification for restricting the UI to Chinese.
Content
No source excerpt is available for this finding.
Unbounded Output
Medium
Category
Output Handling
Confidence
75% confidence
Finding
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
Content
Scanner excerpt · template/dist/assets/index-36bOzI7c.js (reported line 194)May include surrounding context.
This JSX hard-codes user-facing labels in Chinese throughout the global layout, including navigation and search text. The file provides no indication of language selection, opt-in, or justification that the skill is intentionally restricted to a Chinese-only locale, which can violate language/locale policy requirements.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The file imports zh_CN and applies it directly via ConfigProvider locale={zhCN}, which forces a specific language/locale for the entire application. This is a natural-language policy concern because users are not offered a language choice and there is no documented opt-in or region-specific justification in this file.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
86% confidence
Finding
The stylesheet sets the global font-family on html,body to start with "PingFang SC", which is a Simplified Chinese system font. This is a natural-language/locale preference baked into the UI presentation, and the file provides no user choice or documented region-specific justification.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
87% confidence
Finding
The document sets lang="zh-CN", which hard-codes a specific language/locale. Under the policy criteria, forcing a locale without user opt-in or a clearly documented region-specific justification is a natural-language policy concern.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
93% confidence
Finding
The HTML document declares lang="zh-CN", which hard-codes a specific language/locale for the skill interface. Under the policy rules, forcing a locale without offering user opt-in or documenting a justified region-specific constraint is a natural-language policy violation.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: @babel/core==7.29.0 — 1 advisory(ies): CVE-2026-49356 (@babel/core: Arbitrary File Read via sourceMappingURL Comment)
Low
Category
Supply Chain
Confidence
94% confidence
Finding
The lockfile pins @babel/core 7.29.0, and the cited advisory indicates a low-severity arbitrary file read condition tied to processing attacker-controlled sourceMappingURL metadata. In this template, Babel is only a dev dependency transitively used by the Vite React plugin, so the issue is real but primarily affects local build or tooling workflows that ingest untrusted source content rather than deployed runtime behavior.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: @remix-run/router==1.23.2 — 1 advisory(ies): CVE-2026-40181 (React Router's same-origin redirect with path starting // causes open redirect v)
Low
Category
Supply Chain
Confidence
92% confidence
Finding
@remix-run/router 1.23.2 is present and underlies react-router/react-router-dom, so the dependency-level finding is valid. The reported same-origin redirect handling bug can enable open redirects when application code passes attacker-influenced paths beginning with '//' into navigation flows; as a template, this is not immediately exploitable without insecure route usage, but it increases downstream risk.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: baseline-browser-mapping==2.10.12 — 1 advisory(ies): CVE-2026-45819 (baseline-browser-mapping process termination on invalid input causes denial of s)
Low
Category
Supply Chain
Confidence
84% confidence
Finding
baseline-browser-mapping 2.10.12 is included as a dev-time dependency through browserslist, and the advisory describes a denial-of-service crash on invalid input. This is a real package risk, but its scope is limited to tooling that processes malformed or attacker-supplied input during development or CI, not normal production execution of the React template.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: esbuild==0.21.5 — 1 advisory(ies): GHSA-67mh-4wv8-2f99 (esbuild enables any website to send any requests to the development server and r)
Low
Category
Supply Chain
Confidence
96% confidence
Finding
esbuild 0.21.5 is present as part of the Vite toolchain, and the advisory about dev-server request exposure is well-aligned with how esbuild is commonly used. This is a genuine issue, but it is primarily relevant when developers run the local development server on reachable interfaces; it does not by itself indicate a production compromise in the template code.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: react-router==6.30.3 — 3 advisory(ies): CVE-2026-40181 (React Router's same-origin redirect with path starting // causes open redirect v); CVE-2026-53666 (React Router: Arbitrary Constructor Injection via deserializeErrors() in React R); CVE-2026-53669 (React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68)
Low
Category
Supply Chain
Confidence
93% confidence
Finding
react-router 6.30.3 is present and the advisories cover redirect handling and error deserialization risks. The dependency is genuinely vulnerable, but most exploitation depends on how the consuming app uses navigation APIs, loaders/actions, or React Router server features; as a generic template, this elevates supply-chain risk more than it proves a direct exploit path in the provided file alone.
Content
No source excerpt is available for this finding.
Known Vulnerable Dependency: react-router-dom==6.30.3 — 1 advisory(ies): CVE-2026-53668 (React Router: Open redirect leading to XSS)
Low
Category
Supply Chain
Confidence
91% confidence
Finding
react-router-dom 6.30.3 is present and inherits routing/navigation issues that can produce open redirect or XSS chains when unsafe redirect targets are accepted. The finding is therefore valid, but risk is context-dependent and becomes materially dangerous only if the generated application later uses untrusted navigation inputs without validation.