T08 · Insecure Dependencies
- Location
scripts/init_skill.py:63- Finding
Generated Example Recommends an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/init_skill.py, lines 63-70
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
python EXAMPLE_SCRIPT = '''#!/usr/bin/env python3 """ {skill_name} - Helper script Description: What this script does. Usage: python3 scripts/example.py [args] Dependencies: - Python 3.8+ - requests (pip install requests)Technical Analysis
When a user invokes the initializer with
--resources scripts --examples, this template is written into the generatedscripts/example.pyfile. The dependency instructions recommend installingrequestswithout a pinned version, package hash, lockfile, isolated environment, or explicitly trusted package index.Although
requestsis a legitimate package, the generated installation instruction relies on mutable package-index resolution. The installed artifact can vary according to the configured index, dependency resolver, release availability, or a compromised package-distribution environment.Attack Path
- A user creates a Skill with example resources enabled.
- The initializer writes the dependency instruction into
scripts/example.py. - The user follows the generated
pip install requestsinstruction. - Pip resolves the package and transitive dependencies from the user's configured index without version or hash verification.
- If the package source, selected release, transitive dependency, or configured index is compromised, attacker-controlled code can execute during installation or subsequent import.
Impact Assessment
Malicious dependency code would execute with the privileges of the user or automation account running pip or the generated script. Depending on those privileges, the code could access project files, user-readable credentials, environment variables, or other resources available to that account. The issue does not independently ...[truncated 94 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
requestsfrom the generic example because the sample script does not use it. - If a third-party dependency is necessary, place it in a version-controlled requirements file with an exact reviewed version and cryptographic hashes.
- Use a command such as
pip install --require-hashes -r requirements.txt. - Document the expected trusted package index and avoid silently inheriting untrusted index configuration.
- Recommend installation in a dedicated virtual environment with minimal filesystem and credential access.
- Periodically review and update pinned dependencies through a controlled dependency-management process.
- Remove
