T08 · Insecure Dependencies
- Location
references/windows.md:31- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill builds a local Zotero semantic index as advertised, with privacy and reliability cautions but no hidden or malicious behavior found.
Install only if you are comfortable letting the skill read your Zotero database and PDF attachment folder and store derived metadata, embeddings, and PDF text chunks in local JSON files. Use a virtual environment, consider pinning dependencies yourself, keep backups of existing vector-store outputs before full rebuilds, and avoid unusual chunk or batch-size arguments.
references/windows.md:31Unpinned Third-Party Dependencies Create a Supply-Chain Risk
scripts/build_metadata_vectors.py:94Full Rebuild Commands Overwrite Existing Vector Stores Without Backups or Atomic Writes
scripts/zotero_vectorize_lib.py:487Unvalidated Chunking Parameters Can Cause an Infinite Loop and Resource Exhaustion
The declared description centers on vectorizing a Zotero library and maintaining semantic/RAG index files such as metadata_vectors.json and fulltext_vectors.json. This code chunk instead serves a different purpose: making a filesystem snapshot of the Zotero SQLite database. While snapshotting could be a supporting step in a larger indexing workflow, this specific script's primary behavior is backup/copy creation of the database, which is not described. It also does not itself perform any embedding, vector store maintenance, or verification tasks named in the description. Therefore the code chunk is a material mismatch with the declared purpose.
Referenced artifact was not completely inspected
Keep `SKILL.md` focused on workflow. Read the reference files only when needed:
Without declared permissions the skill's intent is opaque and cannot be validated.
The library extracts full text from local PDF attachments and is designed to persist chunked embeddings/store outputs, but this file provides no user-facing consent, sensitivity checks, or warning that potentially confidential document contents will be processed and stored. In the context of a Zotero semantic indexer, that creates a real privacy/security risk because research papers, drafts, legal/medical documents, or licensed content may be silently copied into derived local artifacts that broaden exposure and retention.
The code loads a sentence-transformers model and encodes supplied texts, which are built elsewhere from Zotero metadata and PDF full text. Because model loading can involve network access and users are not warned here that their library content may be processed by an external model stack, this safety-relevant behavior lacks visible disclosure in the code file.
No suspicious patterns detected.