T08 · Insecure Dependencies
- Location
scripts/generate_video.py:2- Finding
Unbounded Dependency Versions Allow Unreviewed Supply-Chain Code
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_video.py:2-7
Vulnerability Type: Unpinned runtime dependencies
Risk Level: MediumVulnerable Code:
python # /// script # requires-python = ">=3.10" # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # ///Technical Analysis
The documented execution method uses
uv run, while the inline dependency metadata permits any future version ofgoogle-genaiandpillowthat satisfies the specified minimum version. Consequently, the dependency code resolved and installed at execution time can differ from the code reviewed during this audit.The script imports
google.genaiand gives the resulting package access to the process environment, Gemini API credentials, prompts, local images, generated media, and the invoking user's filesystem permissions. A compromised or malicious future package release could therefore execute with the same privileges as the user running the Skill.pillowis declared but is not imported or otherwise used by the audited script. Including this unnecessary package expands the dependency and supply-chain attack surface beyond what is required for the declared functionality.Attack Path
- An attacker compromises a permitted dependency release or its package-publishing account.
- The attacker publishes a version satisfying
google-genai>=1.0.0orpillow>=10.0.0. - A user invokes the documented
uv run scripts/generate_video.pyworkflow without a reviewed lockfile. - The dependency resolver selects and installs the compromised release.
- Malicious dependency code executes during import or runtime with the invoking user's privileges.
- The dependency can read accessible process data, including
GEMINI_API_KEY, prompts, supplied media, and local files, or perform unauthorized network and filesystem operations.
Impact Assessment
Exploitation could provide code ...[truncated 468 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than using open-ended minimum versions.
- Generate and commit a lockfile, or use the equivalent locked-script workflow supported by
uv, and enforce locked resolution during execution. - Where supported, verify downloaded distributions using cryptographic hashes.
- Remove
pillowbecause the audited script does not use it. - Review transitive dependencies and update them only through a controlled dependency-review process.
- Run the Skill with restricted filesystem and network access where practical, exposing only the output directory, required input files, and the Google API endpoint.
