T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned VCS Dependency Allows Upstream Code Substitution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16-21andscripts/douyin-web:43-50
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:16-21:bash If the CLI is not installed, install it first: python3 -m pip install "git+https://github.com/billwang233/douyin-web-cli.git" python3 -m playwright install chromium douyin-web --helpscripts/douyin-web:43-50:bash Set one of: DOUYIN_WEB_CLI=/path/to/douyin-web DOUYIN_CLI_ROOT=/path/to/repo Or install the harness: python3 -m pip install "git+https://github.com/billwang233/douyin-web-cli.git" python3 -m playwright install chromiumTechnical Analysis
The installation command retrieves the package directly from the Git repository's moving default branch. It does not specify an immutable commit hash, a signed release, a fixed package version, or an integrity digest.
Consequently, the code executed by
pipcan change after this Skill has been reviewed. Installation may run attacker-controlled package build or setup logic, and subsequent CLI invocations execute the installed code. The use of HTTPS protects the transport channel but does not establish that the retrieved revision is the one that was audited.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
- The attacker adds malicious package installation or runtime code.
- A user or Agent follows the documented installation command.
pipretrieves the current, compromised repository revision and executes its build or installation process.- The malicious package subsequently runs as the invoking user whenever the CLI is used.
Impact Assessment
Exploited code would run with the operating-system privileges of the user invoking
pipor the CLI. Within that privilege boundary, it could access files available t ...[truncated 562 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the Git dependency to a reviewed immutable commit, for example by using a full commit SHA rather than the default branch.
- Prefer a versioned, signed release distributed through a trusted package registry.
- Where package installation supports it, use a lock file and verify cryptographic hashes for downloaded artifacts.
- Record the expected repository, version, commit digest, and verification procedure in
SKILL.md. - Install the dependency into an isolated virtual environment with the minimum permissions required.
- Review dependency changes before updating the pinned revision.
- Avoid running installation as root or with elevated privileges.
