T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This chart-generation skill is broadly coherent and local-only, with documentation and hardening issues users should understand before installing.
Install this only in an environment where installing unpinned Python packages is acceptable. Treat generated HTML/Markdown as trusted-output only unless titles, captions, and width values are escaped or validated, and be aware that the skill documentation overstates language support and mentions web data despite presenting itself as local-only.
SKILL.md:7Unpinned Third-Party Dependencies Create a Supply-Chain Risk
SKILL.md:376HTML Injection Through Unescaped Chart Metadata
The manifest description states a narrower feature set: five chart types and PNG/SVG output only. However, the file documents support for area/stacked charts, CSV/Excel/JSON/directory/text extraction inputs, and PDF/Word/Excel/Markdown/HTML-style embedding, which materially exceeds the stated behavior.
The file claims support for Chinese, English, Japanese, and Korean, yet the requirements-gathering prompt is written only in Chinese and does not instruct the agent to ask the user which language they prefer. This can effectively force a language choice without user opt-in, which conflicts with the locale-policy requirement.
The trigger list includes generic phrases such as "Create a chart," "Data visualization," and "Chart analysis," which can appear in ordinary conversation and many unrelated contexts. The file does not provide exclusion conditions or narrower context constraints, so it is unclear when the skill should activate versus when a general assistant response would be more appropriate.
Step 1 presents the entire interaction template in Chinese only, despite the skill being described as multi-language. Because no opt-in or language-selection step is provided, users may be forced into a specific language regardless of preference.
The feature list advertises 'web' as a supported data source, implying network-based acquisition, while the security notes explicitly claim 'No network calls' and 'Local file processing only.' The code shown contains no network retrieval logic, so the documentation contradicts itself about intended capability.
No suspicious patterns detected.