T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Mandatory Installation of Unpinned Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be straightforward ORBCAFE Kanban UI guidance, with the main caution being ordinary npm dependency-install risk.
Before installing, review and pin the npm dependencies in your own package manifest, use a lockfile or npm ci where possible, and run installation in a normal least-privileged development environment.
SKILL.md:18Mandatory Installation of Unpinned Third-Party Dependencies
This markdown file contains core workflow and verification instructions only in Chinese, which effectively forces a specific language for users following the skill. The policy allows locale constraints only when documented and justified, or when the user is given a language choice, neither of which appears here.
No suspicious patterns detected.