T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned External Repository and Unverified Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–28
Vulnerability Type: Supply-chain risk through mutable external code and unverified Python dependencies
Risk Level: MediumVulnerable Code
bash # Clone repository git clone https://github.com/FujiwaraChoki/MoneyPrinterV2.git cd MoneyPrinterV2 # Requires Python 3.12+ python --version # Create virtual environment python -m venv venv source venv/bin/activate # Windows: .venv\Scripts\activate # Install dependencies pip install -r requirements.txtTechnical Analysis
The Skill directs users to clone the current default branch of an external Git repository and install the dependencies declared by that repository. It does not pin the repository to an audited commit or signed release, verify the downloaded source code, or require cryptographic hashes for Python packages.
As a result, the effective code and dependency set can change after this Skill has been reviewed. A compromised upstream repository could modify application code or
requirements.txt. A compromised or malicious dependency could also execute code during package installation through build-system hooks or when the installed application is subsequently launched.The packaged quick-start script repeats these installation instructions at
scripts/content-automation-quickstart.py:30-36, but it only prints them and does not invokegit,pip, or a shell directly.Attack Path
- An attacker compromises the upstream repository, its default branch, a referenced Python package, or a transitive dependency.
- The attacker adds malicious application code, changes dependency specifications, or publishes a malicious package version accepted by
requirements.txt. - A user follows the Skill instructions and clones the mutable default branch.
- The user runs
pip install -r requirements.txt. - Malicious package build or installation logic executes, or the mal ...[truncated 947 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the external repository to a specific audited commit hash or a cryptographically signed release rather than cloning an unspecified default branch.
- Document the expected commit hash and require users to verify it before installation.
- Replace loosely resolved dependencies with a lock file containing exact package versions and cryptographic hashes.
- Install dependencies using hash enforcement, such as
pip install --require-hashes -r requirements.lock. - Review all direct and transitive dependencies and use automated vulnerability and provenance scanning.
- Prefer vendoring the minimum required implementation into the Skill package so the audited code matches the code that users execute.
- Install and run the external project in an isolated, least-privileged environment without access to unrelated credentials or sensitive host files.
- Avoid placing API and platform credentials in broadly readable plaintext configuration files; restrict file permissions and use an appropriate secret-management mechanism.
