T03 · Remote Payload Retrieval and Execution
Warning
- Location
SKILL.md:127- Finding
Mutable and Integrity-Unverified Third-Party Frontend Resources
- Content
View full analysis
``` ```html ``` ```html ``` ### Technical Analysis The Skill instructs generated frontend applications to retrieve and execute JavaScript directly from third-party CDNs. The Tailwind URL does not specify an exact version, and the Lucide URL explicitly uses the mutable `latest` alias. Consequently, the effective JavaScript payload can change after the Skill has been reviewed. None of the referenced resources uses Subresource Integrity through an `integrity` attribute. Although Flowbite is pinned to version `2.0.0`, the browser has no cryptographic mechanism to verify that the returned resource matches a previously reviewed artifact. This behavior creates a remote payload execution and software supply-chain trust boundary. Any JavaScript returned by these origins executes in the security context of the generated application and can access its DOM and browser-accessible data, subject to browser controls and the application's own security configuration. ### Attack Path 1. A generated frontend incorporates the CDN imports recommended by the Skill. 2. An attacker compromises a referenced CDN, upstream package, package publishing account, or mutable release alias. 3. The attacker causes a malicious JavaScript payload to be served from the expected resource URL. 4. A user visits the generated application, and the browser retrieves the modified resource. 5. Becaus ...[truncated 1061 chars]- Remediation
View remediation
``` 5. Verify hashes against artifacts obtained through a trusted release channel, and update them only after dependency review. 6. Enforce a restrictive Content Security Policy that limits permitted script origins and avoids `unsafe-inline` and `unsafe-eval`. 7. Use automated dependency monitoring and periodically review pinned versions for known vulnerabilities. 8. Clearly restrict CDN-based imports to disposable prototypes and prohibit them in production templates unless integrity verification and version pinning are applied. ]]>
