T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Third-Party Dependencies and Browser Artifacts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not overtly malicious, but it describes unattended automation that imports data into another system over plaintext HTTP with limited safeguards.
Review before installing. Use only in a controlled test or low-risk environment unless you add HTTPS endpoints, pinned dependencies, explicit approval before import, validation of exported row counts/content, logging, and a rollback plan. Avoid enabling the cron job until the import is proven idempotent and monitored.
SKILL.md:27Unpinned Third-Party Dependencies and Browser Artifacts
SKILL.md:14Plaintext HTTP Transport for Data Collection and Upload
The skill explicitly describes exporting data from one system and importing it into another, but it does not warn users that it will perform state-changing actions in the target system. This creates risk of unintended data modification, propagation of incorrect data, and misuse in unattended or poorly reviewed runs, especially because the target operation is an automated import rather than a read-only action.
The cron example encourages unattended recurring execution of an automated export/import workflow without warning that it will continuously move data and trigger write operations in another system. This increases the chance of repeated bad imports, duplication, stale-data propagation, or large-scale operational impact if selectors break or source data changes unexpectedly.
No suspicious patterns detected.