T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Third-Party Executable Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-23
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumyaml install: - kind: uv package: paddleocr bins: [paddleocr]Technical Analysis
The skill directs the runtime to install the
paddleocrpackage without specifying an exact version or an integrity hash. Consequently, installation may resolve to a future package release whose contents differ from the version reviewed during this audit.Because the installed package provides an executable that the skill invokes, malicious package initialization or runtime code could execute with the permissions of the agent process. This creates a supply-chain risk if the package repository, publisher account, release process, or dependency resolution path is compromised.
Attack Path
- An attacker compromises the package publisher, distribution repository, or a future dependency release.
- The attacker publishes malicious code under a version permitted by the unpinned package specification.
- The skill installation process resolves and installs that release.
- Malicious installation or runtime code executes when the package is installed or the
paddleocrexecutable is invoked. - The code can access resources available to the agent process, potentially including submitted documents and the
PADDLEOCR_ACCESS_TOKEN.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the agent process's existing privileges. The resulting scope could include reading files accessible to that process, accessing environment variables such as the OCR access token, modifying writable project data, and making outbound network requests. The configuration does not itself establish elevated privileges or persistence, so impact remains bounded by the permissions and isolation controls of the runtime environment.
- Remediation
View remediation
Remediation Suggestions
- Pin
paddleocrto an exact, reviewed version rather than allowing unconstrained resolution. - Enforce package integrity verification using trusted hashes, signatures, or a lock file supported by the installation environment.
- Retrieve packages only from an explicitly configured and trusted package index.
- Review both direct and transitive dependencies before updating the pinned version.
- Run the CLI in a sandbox with minimal filesystem access, restricted environment-variable exposure, and constrained outbound network access.
- Separate the API token from package installation processes wherever the runtime permits it.
- Pin
