T08 · Insecure Dependencies
- Location
scripts/md-to-pdf.py:1- Finding
Unpinned Runtime Dependency Permits Supply-Chain Substitution
- Content
View full analysis
=3.10" # dependencies = [ # "reportlab", # ] # /// ``` The documented invocation in `SKILL.md`, lines 14–23, executes the script through `uv`: ```bash uv run scripts/md-to-pdf.py input.md uv run scripts/md-to-pdf.py input.md -o output.pdf uv run scripts/md-to-pdf.py input.md --output my-report.pdf uv run scripts/md-to-pdf.py input.md -v ``` ### Technical Analysis The inline dependency declaration specifies `reportlab` without an exact version, lock file, or integrity hash. When the documented `uv run` command is used, `uv` may resolve and install whichever compatible package version is available from the configured package index. Consequently, the effective executable code is not limited to the reviewed project. It also includes mutable third-party package code selected at runtime. A compromised package release, package index, mirror, or resolver configuration could substitute hostile dependency code without requiring a modification to this repository. The project contains no evidence that the current `reportlab` package is malicious. The risk arises from the absence of controls that make dependency resolution reproducible and verify the integrity of downloaded artifacts. ### Attack Path 1. An attacker compromises a compatible `reportlab` release, a configured Python package index or mirror, or the victim's dependency-resolution configuration. 2. The attacker causes a malicious package artifact or release to satisfy the unconstrained `reportlab` dependency. 3. A user follows the documented command and runs the script with `uv run`. 4. `uv` resolves and installs the attacker-controlled dependency when no previously trusted locked environment prevents resolution. 5. Python imp ...[truncated 1009 chars]- Remediation
View remediation
", # ] ``` 2. Generate and commit a `uv.lock` file that records the complete resolved dependency graph. 3. Require locked or frozen dependency installation in documented and automated execution workflows so dependency drift causes failure instead of silent re-resolution. 4. Verify package artifacts with cryptographic hashes where the selected workflow supports them. 5. Retrieve dependencies only from an approved package index or trusted internal mirror, and prevent fallback to untrusted sources. 6. Add automated dependency vulnerability and provenance scanning to the release process. 7. Periodically update the pinned version through a controlled process that includes source review, vulnerability review, testing, and lock-file regeneration. 8. Run the converter with least privilege and restrict filesystem, credential, process, and network access to reduce the impact of a compromised dependency. ]]>
