T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Third-Party Package Installation from Mutable Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–24
Vulnerability Type: Supply-chain risk caused by unpinned dependency installation
Risk Level: MediumVulnerable Code
bash which sports-skills || pip install sports-skillsbash pip install git+https://github.com/machina-sports/sports-skills.gitTechnical Analysis
The Skill instructs the Agent to install
sports-skillswithout pinning an exact package version or validating package hashes. If installation from the package index fails, it directs the Agent to install code from the GitHub repository's mutable default branch rather than from a reviewed commit.Python package installation can execute package-controlled build or installation logic. Furthermore, the installed CLI will execute upstream code when subsequently invoked. The effective code therefore may differ from what existed when this Skill was audited.
The
which sports-skills || pip install sports-skillsconstruction also makes installation the immediate fallback whenever the executable is absent, increasing the likelihood that unreviewed remote code will be fetched and run.No evidence indicates that the current upstream package is malicious. The vulnerability is the absence of version pinning, integrity verification, and provenance controls.
Attack Path
- An attacker compromises the package-index release, an upstream maintainer account, or the GitHub repository.
- The attacker publishes malicious package content or changes the repository's default branch.
- The Agent loads this Skill on a system where
sports-skillsis not installed, or package-index installation fails. - The Agent follows the setup instructions and downloads the attacker-controlled package or repository state.
- Package build or installation logic executes, or the malicious code executes when the installed CLI is invoked.
- The payload runs with the privileges and environmental access of the user operating the Agent ...[truncated 634 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin
sports-skillsto an exact, reviewed release rather than installing the latest available version. -
Maintain a locked requirements file containing cryptographic hashes and install it with hash enforcement, for example:
bash python3 -m pip install --require-hashes -r requirements.txt -
If Git installation is unavoidable, pin a full reviewed commit SHA rather than a branch or tag:
bash python3 -m pip install \ git+https://github.com/machina-sports/sports-skills.git@FULL_REVIEWED_COMMIT_SHA -
Verify release provenance, signatures, or attestations where the upstream distribution mechanism supports them.
-
Replace automatic fallback installation with an explicit confirmation step that displays the source, exact version or commit, and expected integrity value.
-
Install the dependency in an isolated virtual environment with minimum filesystem and credential access.
-
Review dependency updates before changing the pinned version or commit, and update integrity hashes only after approval.
-
