T08 · Insecure Dependencies
Warning
- Location
SKILL.md:17- Finding
Unpinned Third-Party Dependencies Installed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–21
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: MediumVulnerable Code:
markdown The skill uses Python with `pypdf` + `PyMuPDF` (fitz). Install on first use: ```bash pip install pypdf PyMuPDF Pillowtext ### Technical Analysis The skill instructs the agent to install `pypdf`, `PyMuPDF`, and `Pillow` without fixed versions or cryptographic hashes. Consequently, the exact code installed can vary between executions. Dependency resolution may retrieve a newly published, compromised, or otherwise unsafe direct or transitive dependency. Python package installation can execute package build and installation logic with the privileges of the agent process. Although the reviewed project does not contain malicious executable code and does not explicitly select an unofficial package source, the unpinned installation process creates a supply-chain exposure. ### Attack Path 1. An attacker compromises one of the named packages, its distribution account, or a transitive dependency. 2. The attacker publishes a malicious release that remains compatible with the unconstrained package requirement. 3. On first use, the agent follows the instruction and runs `pip install pypdf PyMuPDF Pillow`. 4. `pip` resolves and downloads the attacker-controlled release. 5. Malicious code executes during package installation, import, or subsequent PDF processing with the permissions of the agent process. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the agent's operating-system account. The resulting access could include reading or modifying PDFs and other files accessible to that account, tampering with generated documents, accessing available process credentials or environment variables, and making network requests where permitted. The maximum scope is limited by the privileges and isol ...[truncated 211 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an explicitly reviewed version in a requirements or lock file.
- Pin and review transitive dependencies so dependency resolution is reproducible.
- Record and verify package hashes, for example by installing with
pip install --require-hashes -r requirements.txt. - Explicitly use the approved official or organization-controlled package index and disable unexpected fallback indexes.
- Install dependencies inside an isolated, least-privilege virtual environment or sandbox rather than the agent's global Python environment.
- Prefer organization-approved, preinstalled packages so skill invocation does not perform runtime installation.
- Apply dependency vulnerability scanning and periodically review pinned versions before controlled updates.
