Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/inject-html-editor.mjs <input.html> \
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently creates a local browser-editable copy of an HTML file and does not show hidden network, credential, destructive, or persistence behavior.
Install only if you want a local HTML visual editor. Use it on files you choose, keep the generated editable copy with its assets, and do not run it against live or authenticated webpages; pass --lang en if you prefer English UI.
Referenced artifact was not completely inspected
node scripts/inject-html-editor.mjs <input.html> \
The runtime clearly operates on the current page DOM, uses location.href in draft metadata, injects UI into document.documentElement, and auto-starts without enforcing that the target is a local/saved HTML file. That creates a scope violation: if this skill is invoked on an arbitrary page, it can inspect and modify live page content despite the metadata promising local-only behavior.
The runtime sets DEFAULT_LANG to zh-CN, and the language normalization logic falls back to that default for any non-en value. This means the skill imposes a specific locale unless the caller explicitly overrides it, which is a natural-language locale policy issue because users are not offered a neutral default or explicit opt-in before the language is chosen.
Draft saving stores the full current page URL together with page content patches, which can expose sensitive paths, query parameters, document locations, or identifiers unrelated to the editor’s stated purpose. In the context of a supposedly local HTML editor, persisting full URLs expands data collection beyond what is necessary and can leak browsing or file-location metadata.
On startup, the code writes htmlSlideMenderLanguage as zh-CN whenever options.lang is not exactly en, which silently forces a locale preference into storage. This is a policy concern because the skill selects and persists a specific language without explicit user choice or opt-in.
The code sets the default editor language to "zh-CN" when no language is provided. This is a natural-language locale choice imposed by default rather than offering a neutral default or requiring explicit user selection, which can violate language/locale policy expectations.
The normalizeLanguage function silently maps every value other than "en" to "zh-CN". This enforces a specific locale without user opt-in and may override user intent when they provide another language value.
The markdown explicitly states --lang zh-CN|en with a default of zh-CN, which imposes a language choice unless the user or caller overrides it. The policy allows locale constraints when they are opt-in or clearly justified; here an alternative exists, but the default still forces a specific locale by default.
No suspicious patterns detected.