T08 · Insecure Dependencies
Warning
- Location
SKILL.md:44- Finding
Unpinned Third-Party Dependencies Allow Mutable Supply-Chain Inputs
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:44-49
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash ## Setup Uses uv-managed venv at `.venv/`. To reinstall: ```bash cd ~/.clawdbot/skills/local-whisper uv venv .venv --python 3.12 uv pip install --python .venv/bin/python click openai-whisper torch --index-url https://download.pytorch.org/whl/cputext ### Technical Analysis The documented setup command installs `click`, `openai-whisper`, and `torch` without exact version constraints or cryptographic integrity hashes. Consequently, the dependency resolver may install different package versions each time the setup instructions are executed. Although the configured package index uses HTTPS and there is no evidence that any named dependency is currently malicious, the installation process trusts mutable third-party releases without a reviewed lockfile. A compromised package release, package-index account, or dependency resolution path could introduce unauthorized code after the Skill itself has been reviewed. Python packages can execute code during installation or whenever imported at runtime. Therefore, compromise of a resolved dependency could lead to code execution under the account running the installation or transcription utility. ### Attack Path 1. An attacker compromises a maintainer account, package release, package index, or transitive dependency used by one of the unpinned packages. 2. The attacker publishes a malicious version that remains compatible with the unconstrained package names. 3. A user follows the setup instructions in `SKILL.md`. 4. `uv pip install` resolves and downloads the attacker-controlled release because no lockfile, exact version, or expected hash restricts the selected artifact. 5. Malicious package code executes during installation or later when `transcribe.py` imports and uses the affected dependen ...[truncated 734 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than installing unconstrained package names.
- Generate and commit a reproducible lockfile that records all transitive dependencies.
- Require cryptographic hashes for downloaded artifacts where supported, and fail installation when hashes do not match.
- Explicitly configure and document trusted indexes for all packages. Verify that the selected index contains the required packages and does not cause unsafe fallback behavior.
- Review dependency updates before changing pins, including release provenance, vulnerability advisories, maintainership changes, and transitive dependency differences.
- Install dependencies inside the documented isolated virtual environment as an unprivileged user; do not run the setup command with
sudoor administrative privileges. - Consider using a controlled internal package mirror containing only reviewed artifacts.
An example hardened workflow is to compile reviewed exact versions and hashes into a lockfile, then install exclusively from that file with hash verification enabled.
