T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Python Dependency Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-19
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable configuration:
yaml "install": [ { "id": "requests", "kind": "pip", "package": "requests", "label": "安装依赖:pip3 install requests", }, ]Technical Analysis
The skill installs the third-party Python package
requestswithout specifying an exact version or cryptographic hash. Consequently, pip resolves whichever compatible release is available from the configured package index at installation time. This makes installations non-reproducible and prevents verification that the installed artifact is the version reviewed by the skill author.The dependency name is a legitimate public package, and the audited file contains no evidence that it is currently compromised. However, if the package index, publisher account, dependency resolution path, or local pip configuration were compromised, an attacker-controlled package artifact could be selected. A malicious source distribution or build backend may execute code during package installation.
Attack Path
- An attacker compromises the upstream package publication process, configured pip index, package publisher account, or dependency resolution environment.
- The attacker publishes or serves an altered release under the expected
requestspackage name. - A user installs the skill, causing pip to resolve the unpinned package from the active index.
- Pip downloads and processes the attacker-controlled artifact.
- Malicious build or installation code executes with the privileges of the user or service performing the installation.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installer account. Depending on that account's privileges, the attacker could access files and credentials available to the account, modi ...[truncated 275 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
requeststo a reviewed exact version rather than allowing unconstrained resolution. - Record cryptographic hashes for every permitted distribution and install with
pip --require-hashes. - Maintain dependencies in a version-controlled lock file generated from an audited dependency set.
- Use only a trusted package index and explicitly configure the approved index URL.
- Disable unnecessary supplemental indexes to reduce dependency-confusion exposure.
- Perform dependency vulnerability and provenance checks before updating the pinned version.
- Install dependencies in an isolated virtual environment or container under a non-privileged account.
- Prefer prebuilt, verified wheels and restrict source builds where operationally feasible.
- Pin
