T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Third-Party CLI Dependency Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches its advertised Hologres ad workflow, but it asks for cloud storage/database authority and runs writable SQL templates in a way users should review carefully before installing.
Install only if you intentionally want a Hologres/OSS-based ad generation workflow. Use a pinned, reviewed hologres-cli version in an isolated environment, run with least-privileged Hologres and OSS/RAM roles, avoid pasting secrets, treat signed OSS URLs as private bearer links, and review or rewrite the SQL templates to use parameter binding or strict validation before running them against important data.
SKILL.md:11Unpinned Third-Party CLI Dependency Creates a Supply-Chain Risk
references/sql-templates.md:46SQL Injection Through Direct Substitution of User-Controlled Template Values
The activation text uses very broad trigger phrases covering generic ad/video creation and ROI analysis scenarios, which can cause the skill to activate in contexts beyond the user's intent. Over-broad activation increases the chance that the agent will unnecessarily solicit infrastructure details or initiate SQL-centric workflows for ordinary creative requests, creating avoidable data exposure and unsafe tool use risk.
The skill instructs collection of OSS bucket names, region endpoints, RAM role ARNs, and asset paths without any warning, minimization guidance, or safe-handling boundaries. These infrastructure identifiers can materially aid reconnaissance and, combined with misconfiguration or later leakage, increase the risk of unauthorized access attempts, privilege misuse, or exposure of internal storage topology.
The description contains many broad trigger phrases around advertising, video generation, ROI analysis, and related workflows, which can cause the skill to activate in response to ordinary user discussions instead of clearly scoped requests. Over-broad activation increases the chance of unintended routing, exposing users to unexpected SQL-driven actions or analytics behavior they did not explicitly request.
The description is fully Chinese-language and appears to assume Chinese-language behavior without stating a locale constraint or user opt-in path. This can cause incorrect activation or mismatched responses for users in other languages, creating confusion and increasing the risk of unintended execution in multilingual environments.
The SQL templates send product materials and OSS/local file references to external AI generation functions (ai_gen, to_file) without any notice, consent, or data-classification guidance. In an ad-creation workflow, uploaded assets may include proprietary creative, customer data, or licensed media, so silent transmission to remote model services creates confidentiality and compliance risk.
This section documents full ad-video generation through remote AI processing and explicitly instructs preserving signed video URLs containing access parameters such as Expires, OSSAccessKeyId, and Signature. Exposing or broadly sharing signed URLs can grant unintended access to generated media, and the lack of any warning increases the chance of accidental leakage of sensitive or proprietary campaign assets.
This markdown file presents all user-facing instructions and templates exclusively in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language option or justification is provided.
Natural-language instructions and embedded prompt templates are Chinese-only throughout the file, which can impose a language constraint on users and downstream model behavior. The file does not offer an alternative language option or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context.
No suspicious patterns detected.