T08 · Insecure Dependencies
- Location
assets/template.html:7- Finding
Unpinned and Remotely Loaded Presentation Dependencies
- Content
View full analysis
``` `assets/template-journal.html:7-8`: ```html ``` The remote dependencies are also prescribed by the supporting documentation: ```markdown - [ ] Lucide CSS introduced correctly (`https://unpkg.com/lucide-static@latest/font/lucide.min.css`) - [ ] Remix Icon CSS introduced correctly (`https://cdn.jsdelivr.net/npm/remixicon@3.5.0/fonts/remixicon.css`) ``` ### Technical Analysis The generated HTML automatically retrieves stylesheets and associated font resources from Google Fonts, unpkg, and jsDelivr when opened in a browser. Consequently, the output is not fully self-contained or offline despite being described as a single-file document that can be opened locally. The Lucide dependency uses the mutable `@latest` version selector. Its effective contents can therefore change after this Skill has been reviewed, without any corresponding change to the project. None of the remote stylesheet references includes Subresource Integrity verification. A compromised package release, CDN account, distribution path, or upstream service could return modified CSS. Remote CSS does not ordinarily provide arbitrary native code execution, but it can modify document prese ...[truncated 2029 chars]- Remediation
View remediation
