T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:215- Finding
Unpinned Remote JavaScript Executed in Generated Prototypes
- Content
View full analysis
产品原型 - {产品名称} ``` The Skill also explicitly prescribes `Tailwind CSS (CDN)` at line 101. ### Technical Analysis The generated prototype loads JavaScript from the mutable URL `https://cdn.tailwindcss.com`. This is a runtime compiler script rather than a locally generated stylesheet. No immutable version, Subresource Integrity hash, or locally vendored copy is required. Consequently, the effective executable content can change after the Skill and generated HTML have been reviewed. If the CDN, its publishing process, or the referenced upstream resource is compromised, attacker-controlled JavaScript will execute when a user opens the prototype. The remote script runs in the prototype's browser execution context. It can access and modify the page DOM, capture values entered into prototype forms, inspect browser-side state available to that page, alter displayed content, and initiate outbound requests. The remote dependency also contradicts the delivery claim that the prototype is a self-contained HTML file that requires no server or deployment. ### Attack Path 1. The Agent follows the Skill and generates an HTML prototype containing the prescribed script element. 2. A user opens the generated prototype in a browser. 3. The browser requests executable JavaScript from `https://cdn.tailwindcss.com`. 4. The CDN resource or its upstream publishing process has been compromised or modified after the prototype was reviewed. 5. The browser executes the modified JavaScript within the prototype page. 6. The payload reads or changes page-visible info ...[truncated 1108 chars]- Remediation
View remediation
