T08 · Insecure Dependencies
- Location
references/template.md:48- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is purpose-aligned for drafting IT proposals, but it persists sensitive proposal state and cloud folder tokens locally and uploads final documents to Feishu without enough scoping or retention guidance.
Install only if you are comfortable with local plaintext proposal state files and Feishu cloud upload. Before use, confirm where state files are stored, avoid saving sensitive infrastructure details or credentials, delete proposal JSON files after completion, and prefer a pinned dependency setup for python-docx.
references/template.md:48Unpinned Third-Party Dependency Installation
SKILL.md:30Plaintext Persistence of a Cloud Folder Token in Workflow State
The pause/resume trigger phrases are broad enough to match ordinary conversation, which can cause the skill to save, pause, or resume unexpectedly. In this skill, that can lead to unintended persistence of sensitive proposal content or loading the wrong saved proposal, especially because the content may involve government, state-owned enterprise, or security-planning information.
The skill instructs the system to persist full proposal state to local JSON files without an explicit user warning or consent flow. Because proposals may contain internal planning, network/security details, budgets, and other sensitive enterprise information, silent local retention increases the risk of privacy leakage, accidental disclosure, and over-retention.
The workflow directs the generated document to be uploaded to Feishu cloud storage but does not clearly warn users that potentially sensitive proposal data will leave local processing and be stored in a third-party cloud environment. Given the stated use cases include government, SOE, and cybersecurity planning documents, unannounced cloud upload materially raises confidentiality and compliance risk.
The document explicitly requires a specific language/style regime, including '政府公文风格' and banned expressions, which effectively forces output into a particular locale/register. Because the file does not indicate user opt-in or that this is a narrowly justified regional/compliance-only skill, it creates a natural-language policy concern under the language/locale rule.
The state schema marks folder_token as optional at L064, but the documented workflow at L155 requires uploading the final document to a specified Feishu cloud folder. This is a documentation-level contradiction about whether that value is required for the promised completion path.
No suspicious patterns detected.