T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This PDF skill is a straightforward document-processing guide; its file access and PDF-writing examples fit the stated purpose, though users should run examples carefully to avoid overwriting files.
Install only the PDF/OCR packages you need, preferably in a virtual environment with reviewed pinned versions. Before running examples, change input and output paths to explicit safe filenames, avoid running them in directories with important PDFs, and escape or validate any untrusted data used to generate HTML-based PDFs.
SKILL.md:19Unpinned Third-Party Dependencies Create Supply-Chain Exposure
SKILL.md:502Unescaped Report Data Is Interpolated into HTML Before PDF Rendering
The skill contains many copy-pastable examples that create, overwrite, merge, split, encrypt, and delete local files without prominent safety warnings or guidance to use safe output paths. In an agent-skill context, a model may operationalize these examples on real user files or in the current working directory, causing unintended data modification, overwrite, or deletion even though the code is presented as documentation.
No suspicious patterns detected.