T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:35-39
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
bash ## Install ```bash uv tool install kokoro-ttstext ### Technical Analysis The installation command retrieves and installs the current version of the third-party `kokoro-tts` package without pinning an audited version or verifying its integrity. This package supplies the executable behavior of the Skill, but its source and transitive dependencies are not included in the audited project. Because dependency resolution occurs at installation time, the effective executable payload can change after this Skill has been reviewed. A compromised publisher account, malicious future release, package ownership transfer, or compromised transitive dependency could introduce attacker-controlled code. Installing the TTS implementation is necessary for the declared functionality, and the command does not request administrative privileges. Nevertheless, allowing an unpinned package to execute with the invoking user's permissions exceeds the minimum supply-chain trust needed when a fixed, reviewed version could be specified. ### Attack Path 1. An attacker compromises the package publisher, distribution account, or a resolved dependency. 2. The attacker publishes a malicious package version that still satisfies the unpinned package name. 3. A user follows the Skill's installation instruction. 4. `uv` retrieves and installs the attacker-controlled release. 5. Malicious installation or runtime behavior executes with the permissions of the invoking user when the package is installed or used. ### Impact Assessment Successful exploitation could permit arbitrary code execution in the user's security context. Depending on that user's existing permissions, the compromised package could read or modify accessible files, access available credentials or environm ...[truncated 182 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
kokoro-ttsto a specific reviewed version rather than resolving the latest available release. - Use a lockfile or equivalent mechanism to pin all transitive dependencies.
- Require hashes for downloaded package artifacts where supported.
- Document the expected package publisher and canonical source repository.
- Review the pinned package and its dependency graph before recommending installation.
- Obtain explicit user approval before installing external executable dependencies.
- Run the tool with ordinary user permissions and, where practical, inside an isolated environment with only the input and output paths required for TTS.
- Pin
