T08 · Insecure Dependencies
- Location
README.md:60- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This exam stress coaching skill is purpose-aligned and locally scoped, but users should understand that stress notes and generated plans are saved as plaintext files.
Install and run this only from a trusted copy, preferably in a virtual environment with pinned dependencies. Avoid putting highly sensitive details in stress notes, and delete or protect stress_log.json if the machine, project folder, backups, or sync services are shared. Be careful with --output because it can overwrite files your account can write.
README.md:60Unpinned Third-Party Dependency Installation
scripts/stress_coach.py:451Arbitrary Writable File Overwrite Through the Plan Output Path
scripts/stress_coach.py:300Sensitive Stress Records Stored in Plaintext Without Explicit Access Controls
The README promotes logging stress levels and free-form notes over time but does not warn users that these entries may be stored persistently on disk. Because stress notes can contain sensitive mental-health, academic, or personal context, users may disclose more than intended, creating privacy risk if the device is shared, compromised, or backed up to less secure locations.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill instructs users to log daily stress levels and notes to a JSON file without warning that this creates local records of potentially sensitive mental-health-related information. Even if stored only locally, users may not realize this data persists, could be readable by other local users/processes, or may be included in backups and sync services.
No suspicious patterns detected.