T08 · Insecure Dependencies
- Location
package.json:14- Finding
Non-Reproducible Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This OCR skill is purpose-aligned and disclosed, with manageable supply-chain and network-download considerations before installation.
Before installing, understand that npm will fetch Tesseract.js and the first OCR run may download language data of about 20MB per language. For stricter environments, pin dependencies, add a lockfile, and review the installed tesseract.js version before use.
package.json:14Non-Reproducible Third-Party Dependency Installation
This markdown file is entirely written in Chinese, including operational instructions and publication guidance, with no indication that users may choose another language or that the locale restriction is required for a region-specific purpose. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.
This markdown file documents that the first run downloads Tesseract.js language data, but it presents the behavior only as a note and does not clearly warn users that running the skill will initiate a network download. Because the skill affects privacy/system behavior by making a network transfer, the description should disclose that more explicitly before use.
The package description states that the skill supports only Chinese (simplified/traditional) and English. Under the policy for natural-language violations, constraining language/locale without offering user choice or documenting a justified regional limitation can be a policy issue.
The dependency uses a caret range (^7.0.0), which allows installation of future minor and patch releases that have not been reviewed for this skill. This weakens supply-chain integrity and can unintentionally pull in vulnerable or behavior-changing versions during installation or rebuilds.
"license": "MIT",
"acceptLicenseTerms": true,
"dependencies": {
"tesseract.js": "^7.0.0"
},
"repository": {
"type": "git",
The manifest references tesseract.js without pinning an exact version, while there is a known advisory affecting some releases. Because the resolved installed version is not fixed or evidenced by a lockfile, consumers cannot verify whether they are exposed to the insecure default configuration issue.
No suspicious patterns detected.