T08 · Insecure Dependencies
- Location
scripts/pinterest_api.py:15- Finding
Unpinned Dependency Is Automatically Downloaded and Installed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
scripts/pinterest_api.py, lines 15-21
Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: MediumVulnerable code:
python try: import httpx except ImportError: print("Installing httpx...") import subprocess subprocess.check_call([sys.executable, "-m", "pip", "install", "httpx", "-q"]) import httpxTechnical Analysis
When
httpxis unavailable, the script invokespipto download and install the package without specifying an audited version, cryptographic hash, or trusted package index. Package installation executes package-controlled build and installation logic within the privileges of the Python process.Consequently, the code executed by the skill can change independently of the reviewed project. Although
httpxis a legitimate package, a compromised upstream release, compromised or attacker-controlled Python package index, poisoned package mirror, or unsafe localpipconfiguration could cause malicious package code to be installed and executed.The use of an argument array rather than a shell command prevents conventional shell injection at this call site, but it does not address the dependency supply-chain risk.
Attack Path
- The skill is executed in an environment where
httpxis not already installed. - An attacker compromises the configured package source or causes
pipto use an attacker-controlled index or mirror. A malicious upstream release would create the same risk. - The import raises
ImportError, entering the automatic installation branch. - The script executes
python -m pip install httpx -qwithout a version or hash constraint. pipdownloads the attacker-controlled distribution and runs any applicable build or installation code.- The script imports the installed package, allowing malicious module initialization code to execute again.
...[truncated 609 chars]
- The skill is executed in an environment where
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from application runtime. If
httpxis missing, terminate with a clear dependency error. - Declare dependencies in a dedicated dependency manifest and lock file.
- Pin
httpxand all transitive dependencies to reviewed versions. - Require cryptographic hashes during installation, such as with a hash-locked requirements file and
pip install --require-hashes. - Install dependencies during a controlled build or deployment stage from an explicitly configured trusted index.
- Run the skill in a least-privileged virtual environment or isolated container.
- Perform dependency vulnerability and provenance scanning in CI, and update pinned versions through a reviewed process.
A safer runtime pattern is:
python try: import httpx except ImportError as exc: raise RuntimeError( "Missing required dependency 'httpx'; install the project's locked dependencies." ) from exc- Remove automatic package installation from application runtime. If
