T08 · Insecure Dependencies
- Location
scripts/generate_video.py:2- Finding
Unbounded Runtime Dependency Resolution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_video.py, lines 2–7
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
python # /// script # requires-python = ">=3.10" # dependencies = [ # "google-genai>=1.0.0", # ] # ///Technical Analysis
The script declares
google-genaiusing the open-ended constraint>=1.0.0. The documenteduv runworkflow may resolve and install the dependency dynamically, but the project provides no exact version pin, upper bound, lockfile, or integrity hash.Consequently, a future release satisfying this constraint can be loaded without having been reviewed with the Skill. Imported dependency code executes within the Skill's process and inherits access to its environment and filesystem. This includes access to
GEMINI_API_KEY, user-selected reference images, generated video files, and other resources available under the invoking user's permissions.This finding concerns uncontrolled dependency resolution. The audited code does not establish that the current
google-genaipackage is malicious.Attack Path
- An attacker compromises the upstream package, its publishing account, or a future compatible release.
- The attacker publishes a malicious version satisfying
google-genai>=1.0.0. - A user invokes the documented
uv runcommand in an environment where that version is selected. uvretrieves and installs the newly resolved version.- The script imports
google.genai, causing package-controlled code to execute with the invoking user's privileges. - The compromised dependency can read inherited environment variables, access files available to the process, modify output, or communicate with external systems.
Impact Assessment
Successful exploitation would provide code execution at the privilege level of the user running the Skill. The reachable scope includes the Skill proc ...[truncated 329 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
google-genaito an exact, reviewed version rather than using an open-ended lower bound. - Commit a lockfile generated by
uvand run the Skill with locked or frozen dependency resolution. - Where supported, verify downloaded artifacts using cryptographic hashes.
- Configure package installation to use an explicitly trusted package index and disallow unexpected alternate sources.
- Update dependencies through a controlled process that includes security review, automated vulnerability scanning, and testing.
- Run the Skill with least privilege and provide only the environment variables and filesystem access required for video generation.
- Pin
