T08 · Insecure Dependencies
- Location
SKILL.md:81- Finding
Generated Reports Load Mutable Third-Party JavaScript Without Integrity Verification
- Content
View full analysis
``` ### Technical Analysis The Skill requires generated HTML reports to load ECharts from jsDelivr using the mutable major-version selector `echarts@5`. This selector does not identify an exact, audited artifact and may resolve to a different ECharts release in the future. The script element also lacks a Subresource Integrity (`integrity`) attribute. Consequently, the browser has no cryptographic mechanism to verify that the downloaded JavaScript is the version expected when the Skill was reviewed. Because third-party JavaScript executes with the privileges of the generated report's browser context, compromise of the CDN, package publication process, package maintainer account, or dependency resolution path could cause unauthorized code to execute whenever a report is opened. ### Attack Path 1. An attacker compromises the ECharts package publication channel, the CDN delivery path, or another component capable of changing the resource resolved by `echarts@5`. 2. The mutable CDN resource is replaced or made to resolve to modified JavaScript. 3. The Skill generates an HTML patent report containing the affected script element. 4. A user opens the generated report while connected to the network. 5. The browser downloads the modified JavaScript without performing an integrity check. 6. The attacker-controlled script executes in the report's browser context. 7. The script can read and modify report content, including patent analysis data rendered in the document, and may transmit accessible information to an attacker-controlled endpoint. ### Impact Assessment Successful expl ...[truncated 650 chars]- Remediation
View remediation
``` 2. Generate the `integrity` value from the exact deployed artifact and verify it independently before release. Do not use the placeholder shown above. 3. Prefer bundling a verified local copy of ECharts with the Skill or generated report when offline operation is acceptable. Record its version and cryptographic checksum. 4. Establish a controlled dependency-update process: - Review release notes and security advisories. - Verify package provenance. - Test the exact artifact. - Update the pinned version and integrity hash together. - Re-run the security audit after each update. 5. Apply a restrictive Content Security Policy to generated reports. Limit `script-src` to the required local resource or specifically approved CDN resource and restrict outbound connections through `connect-src`. 6. Update both affected templates so generated reports cannot fall back to the mutable, non-integrity-protected URL. ]]>
