T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Unpinned Third-Party Dependencies Permit Mutable Supply-Chain Resolution
- Content
View full analysis
=2.28.0 beautifulsoup4>=4.11.0 rapidfuzz>=3.0.0 \`\`\` Install: `pip install requests beautifulsoup4 rapidfuzz` ``` The corresponding installation instructions in `README.md:18-22` are: ```markdown ### Install dependencies \`\`\`bash pip install requests beautifulsoup4 rapidfuzz \`\`\` ``` ### Technical Analysis The project instructs users to install dependencies directly by package name and permits mutable versions through lower-bound constraints. It does not provide a lockfile, exact version pins, artifact hashes, or an explicitly trusted package index. Consequently, the source code reviewed in this repository does not uniquely determine the code installed into the runtime environment. Pip may resolve newer direct or transitive dependency versions that were not reviewed with the skill. If a dependency release, transitive dependency, or configured package index is compromised, attacker-controlled package content could be introduced into the environment. This is a supply-chain hardening weakness rather than evidence that any currently named dependency is malicious. ### Attack Path 1. A user follows the documented `pip install` command. 2. Pip queries the user's configured package index and resolves current versions of the named packages and their transitive dependencies. 3. A direct or transitive dependency has been compromised, or the environment is configured to use an attacker-controlled or unsafe package index. 4. Pip downloads and installs the attacker-controlled artifact because no exact version or hash validation is required. 5. Malicious dependency code executes when imported or u ...[truncated 934 chars]- Remediation
View remediation
beautifulsoup4== rapidfuzz== ``` 2. Generate and commit a lockfile containing resolved transitive dependencies. Use an appropriate tool such as `pip-tools`, Poetry, or uv. 3. Record cryptographic hashes for every permitted distribution and require hash verification during installation: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Generate the hashes from trusted artifacts obtained from the official Python Package Index or an organization-controlled mirror. 5. Document the expected package index and avoid configurations that merge an internal index with an untrusted public source in a way that enables dependency confusion. 6. Run dependency vulnerability and provenance checks in CI, and review updates before regenerating the lockfile. 7. Install the project in an isolated virtual environment or container under a minimally privileged account. 8. Update both `SKILL.md` and `README.md` so that their installation commands use the locked, hash-verified manifest rather than resolving packages by unpinned names. ]]>
