T08 · Insecure Dependencies
- Location
SKILL.md:161- Finding
Unpinned Runtime Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 161–165
Vulnerability Type: Unpinned third-party package installation at runtime
Risk Level: MediumVulnerable Code Snippet:
markdown #### Option 1 (preferred): `run_command` + Python PIL Test the environment first: ```bash python3 -c "from PIL import Image; print('ok')" 2>/dev/null || pip install Pillow -qTechnical Analysis
If the Pillow import fails, the Skill instructs the agent to install
Pillowdynamically from the package index configured forpip. The dependency is not pinned to a reviewed version, verified against a cryptographic hash, resolved through a lock file, or restricted to an explicitly approved package repository.As a result, installation behavior depends on mutable external package-index state and local
pipconfiguration. A compromised package release, compromised repository, or attacker-controlled package index or mirror could supply malicious installation artifacts. Package installation and subsequent imports may execute attacker-controlled Python code with the privileges of the agent process.The quiet option (
-q) also reduces installation output, making repository changes or unexpected dependency resolution less visible during execution.Attack Path
- Pillow is absent or deliberately made unavailable in the runtime environment.
- The initial
python3import command exits unsuccessfully. - The shell executes
pip install Pillow -qthrough the||branch. pipresolves the package using the environment's configured index and mirror settings.- A compromised release, repository, mirror, or hostile index supplies a malicious distribution.
- Malicious code executes during package installation or when the installed package is imported.
- The code gains access to resources available to the agent process.
Impact Assessment
Successful exploitation could permit arbitrary code ...[truncated 512 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic dependency installation from the Skill workflow.
- Declare Pillow as a preinstalled dependency in a reviewed deployment image or controlled environment specification.
- Pin Pillow to a reviewed exact version rather than resolving the latest available release.
- Use a lock file with cryptographic hashes and enforce installation with
pip install --require-hashes. - Restrict package resolution to an approved, authenticated repository or internal mirror.
- Install dependencies during a controlled build phase rather than while processing user requests.
- Run dependency installation and image processing in a sandboxed, least-privilege environment without unnecessary secrets or filesystem access.
- If Pillow is unavailable at runtime, use the documented no-install fallback instead of modifying the environment automatically.
- Preserve and review package-manager logs rather than suppressing relevant installation output with
-q.
