T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Global Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Expo/React Native scaffolding guide, but it gives production app guidance that can store auth tokens insecurely and asks users to run broad unpinned install commands.
Review the install commands before running them, prefer project-local pinned dependencies, and require SecureStore/Keychain/Keystore for authentication secrets. Treat notification token sync, Sentry, Firebase, and auth metadata as privacy-impacting features that need explicit user consent, minimization, and logout or revocation handling.
SKILL.md:18Unpinned Global Third-Party Dependency Installation
SKILL.md:145Authentication Tokens May Be Persisted in Unencrypted AsyncStorage
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
### 1. `src/navigation/RootNavigator.tsx` (The Gatekeeper)
Implement the `RootNavigator` stack using the centralized logic:
- **Centralized Options**: Consuming `navigationOptions` from `useAppStyle`.
- **Key-Based Remounting**: Use `key={isAuthenticated ? 'authed' : 'guest'}` on the navigator to clear state during transitions.
## 🟡 Step 4: Implementation (Main Navigator)
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## [1.0.0] - 2026-04-07
### ✨ Added
- **Clawhub Mobile Skill**: Created standardized `.agents/skills/clawhub-mobile/SKILL.md` for intelligent agent guidance.
- **Master Skill Migration**: Rebranded and cleaned `expo-master.md` to align with Clawhub architecture.
- **ProductDetail Example**: Implemented a reference feature screen demonstrating the mandatory 4-file pattern:
- `index.tsx` (Pure UI / 4-State Rendering)
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill explicitly instructs implementing token persistence for tokens and user metadata but does not require informing the user that sensitive authentication material may be stored on-device. In a provisioning skill that scaffolds production-ready mobile apps, omission of this warning can normalize insecure defaults or lead operators to persist sensitive data without considering retention, encryption, device compromise, or privacy requirements.
The skill directs implementation of notification token synchronization tied to auth state and message-driven refresh actions, but it omits any warning that device push tokens and related identifiers will be transmitted to backend services and linked to user accounts. This matters because push tokens are device-linked identifiers that can affect privacy, consent, and backend trust boundaries, especially in a production mobile app scaffold intended for reuse.
The skill instructs users to install global packages and run setup commands without an explicit warning that these actions modify the host system and may fetch code from external registries. In an agent-skill context, operational commands that change the environment are more sensitive because users may treat the skill as trusted automation guidance and execute commands without reviewing their effects.
No suspicious patterns detected.