T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Python Dependencies Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–17
Vulnerability Type: Unpinned third-party Python dependencies
Risk Level: MediumCode Snippet:
json "kind": "pip", "package": "pandas openpyxl",Technical Analysis
The skill declares
pandasandopenpyxlwithout exact versions or integrity hashes. Consequently, installation resolves whichever compatible releases are available from the configured Python package index at installation time.This makes installations non-reproducible and leaves the skill exposed to upstream package compromise, a compromised package index, malicious dependency substitution in an untrusted index, or future releases containing security regressions. Python packages distributed as source archives may execute build backend logic during installation; installed package code also executes when imported or invoked.
The declared package names are established packages, and the audited file does not specify a malicious source or contain evidence that either dependency is currently compromised. The issue is the absence of controls that ensure reviewed dependency artifacts are installed.
Attack Path
- An attacker compromises a declared package, one of its transitive dependencies, or a package index trusted by the installation environment.
- The attacker publishes or substitutes a malicious release matching the unconstrained dependency declaration.
- A user installs the skill dependencies after that release becomes available.
pipresolves and installs the attacker-controlled artifact because no exact version or hash is enforced.- Malicious code runs through package build hooks, installation-related behavior, or subsequent package import and use.
Impact Assessment
Exploited dependency code would generally run with the privileges of the account performing installation or executing the skill. It could access files, environment variables, credent ...[truncated 426 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each direct dependency to an exact, reviewed version, for example:
text pandas==REVIEWED_VERSION openpyxl==REVIEWED_VERSION - Generate and commit a lock file that also pins all transitive dependencies.
- Require cryptographic hashes for every permitted artifact, such as by installing from a hash-locked requirements file with
pip --require-hashes. - Use an explicitly configured, trusted package index or an internally controlled artifact repository.
- Prefer reviewed binary wheels where appropriate and prevent unexpected source builds in deployment environments.
- Run dependency installation and skill execution as a non-privileged account in an isolated virtual environment or container.
- Add automated dependency vulnerability and provenance scanning, and update pinned versions through a controlled review process.
- Pin each direct dependency to an exact, reviewed version, for example:
