T08 · Insecure Dependencies
- Location
README.md:68- Finding
Mutable and Unverifiable Third-Party Skill Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 68-75;workflow.json, lines 9-74
Vulnerability Type: Supply-chain exposure through unpinned third-party Skills
Risk Level: MediumVulnerable Code Snippet
markdown ## Dependent Individual Skills | Skill | Version | Purpose | |-------|------|------| | ai-news-daily | 1.0.3+ | Global AI news collection | | agent-reach | latest | Multi-platform in-depth research | | Public Account Assistant | latest | Long-form writing and formatting | | nano-banana-pro | latest | AI cover image generation | | wechat-mp-cn | latest | WeChat Official Account publishing | | xiaohongshu-mcp | latest | Xiaohongshu content publishing |The original dependency declarations use a minimum-version range for
ai-news-dailyand the mutablelatestversion for the other listed Skills. The workflow also identifies dependencies only by Skill name:json { "phase": 2, "name": "Deep Research", "skill": "agent-reach" }, { "phase": 3, "name": "Article Writing", "skill": "Public Account Assistant" }, { "phase": 4, "name": "Cover Generation", "skill": "nano-banana-pro" }, { "phase": 5, "name": "WeChat Publishing", "skill": "wechat-mp-cn" }, { "phase": 6, "name": "Xiaohongshu Publishing", "skill": "xiaohongshu-mcp" }Technical Analysis
The workflow delegates network research, content generation, image generation, and authenticated publishing to external Skills. Most dependencies are referenced using
latestor without any version, artifact hash, signature, trusted publisher identifier, or immutable source location.Consequently, the implementation executed at runtime may differ from the implementation that was originally reviewed. A compromised publisher account, malicious update, registry substitution, or similarly named component could alter a dependency after approval. This is ...[truncated 1717 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every external Skill to an exact, reviewed version rather than
latest, a minimum-version range, or an unversioned name. - Record immutable artifact hashes, signatures, and trusted publisher identities in the workflow or an associated lock file.
- Resolve dependencies exclusively through an allowlisted registry or repository with signature verification enabled.
- Review dependency updates before changing the lock file; do not update automatically in the production publishing workflow.
- Grant each Skill only the permissions required for its phase. Research and writing Skills should not receive publishing credentials.
- Isolate publishing connectors and provide short-lived, narrowly scoped tokens wherever the target platform supports them.
- Generate and retain a dependency inventory so the exact implementations used for each workflow execution can be audited.
- Pin every external Skill to an exact, reviewed version rather than
