T08 · Insecure Dependencies
- Location
references/expo.md:28- Finding
Unpinned npx Commands May Download and Execute Untrusted Package Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local App Store readiness audit skill with no hidden exfiltration or persistence, though users should be careful with optional commands that write files or download tooling.
Install only if you are comfortable with a local audit script reading repository metadata and filenames. Use the default read-only command first, keep --json to a simple repo-local filename such as audit.json, and avoid the optional npx Expo commands unless you trust the package source or run a pinned/local version.
references/expo.md:28Unpinned npx Commands May Download and Execute Untrusted Package Code
scripts/audit.mjs:930Unrestricted JSON Output Path Permits Overwriting Files Outside the Repository
Referenced artifact was not completely inspected
Prefer scripted detection (`audit.mjs`). If doing manually:
Referenced artifact was not completely inspected
Prefer scripted detection (`audit.mjs`). If doing manually:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
status: "FAIL",
title: "Potential secret/signing artifacts tracked in repo",
evidence: [...secrets.bad, ...secrets.sshKeys].slice(0, 50).join("\n"),
remediation: "Remove these files from the repo history and rotate any compromised credentials. Use keychain/CI secrets instead.",
});
} else if (secrets.envFiles.length) {
checks.push({
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
evidence: [...secrets.bad, ...secrets.sshKeys].slice(0, 50).join("\n"),
remediation: "Remove these files from the repo history and rotate any compromised credentials. Use keychain/CI secrets instead.",
});
} else if (secrets.envFiles.length) {
checks.push({
id: "secrets-env",
status: "WARN",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
evidence: [...secrets.bad, ...secrets.sshKeys].slice(0, 50).join("\n"),
remediation: "Remove these files from the repo history and rotate any compromised credentials. Use keychain/CI secrets instead.",
});
} else if (secrets.envFiles.length) {
checks.push({
id: "secrets-env",
status: "WARN",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
checks.push({
id: "secrets-env",
status: "WARN",
title: "Possible .env files tracked in repo",
evidence: secrets.envFiles.slice(0, 50).join("\n"),
remediation: "Ensure .env files contain no secrets, or remove from git and document a template (.env.example).",
});
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
checks.push({
id: "secrets-env",
status: "WARN",
title: "Possible .env files tracked in repo",
evidence: secrets.envFiles.slice(0, 50).join("\n"),
remediation: "Ensure .env files contain no secrets, or remove from git and document a template (.env.example).",
});
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
checks.push({
id: "secrets-env",
status: "WARN",
title: "Possible .env files tracked in repo",
evidence: secrets.envFiles.slice(0, 50).join("\n"),
remediation: "Ensure .env files contain no secrets, or remove from git and document a template (.env.example).",
});
The skill invokes executable commands (node ..., xcodebuild ...) and contemplates file modification via apply_patch, but the manifest does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where an agent may have broader-than-intended access to execution or environment capabilities, increasing the chance of unsafe command use or privilege creep.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common compliance pitfalls
- Missing permission strings when using Expo modules:
- Expo modules often require you to set usage strings via config plugins or `expo.ios.infoPlist`.
- Tracking:
- If using tracking/ad SDKs or `expo-tracking-transparency`, ensure `NSUserTrackingUsageDescription` and ATT flow.
- Native modules / prebuild:
Detected: suspicious.dangerous_exec