T08 · Insecure Dependencies
- Location
scripts/read_paper_main.py:126- Finding
Automatic Installation of Unpinned Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
scripts/read_paper_main.py, lines 126-129 and 151-155
Vulnerability Type: Supply-chain exposure through runtime package installation
Risk Level: MediumVulnerable Code:
python subprocess.check_call([ sys.executable, '-m', 'pip', 'install', package_name, '-q', '--disable-pip-version-check' ])The package names passed to this installation routine are:
python libraries = [ ('pymupdf', 'fitz'), # PyMuPDF ('pdfplumber', 'pdfplumber'), # pdfplumber ('pypdf', 'pypdf'), # pypdf ]Technical Analysis
When a required PDF library is unavailable, the skill automatically invokes pip to download and install it. The dependencies have no fixed versions, integrity hashes, trusted-index restrictions, or lock-file controls. The effective code installed during execution can therefore change independently of the reviewed skill package.
Python package installation may execute package build logic and subsequently imports the installed package into the skill process. As a result, compromise of a package release, configured package repository, dependency resolution path, or network distribution channel could introduce arbitrary code into the agent environment.
This is not evidence that the named packages are malicious. The vulnerability is the mutable and unverified runtime dependency installation process.
Attack Path
- The skill runs in an environment where one or more PDF-processing libraries are missing.
ensure_package_installedinvokes the environment's configured pip client.- Pip resolves the package from its configured package index without enforcing a reviewed version or package hash.
- An attacker who has compromised the relevant package release, index, mirror, or dependency-resolution configuration supplies malicious package content.
- Installation or subsequent import executes the ma ...[truncated 623 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic runtime installation and declare dependencies through a standard project manifest.
- Pin every direct and transitive dependency to a reviewed version in a lock file.
- Require package hashes, such as with pip's
--require-hashes, to verify artifact integrity. - Install dependencies during a controlled deployment or build stage rather than when processing a user document.
- Restrict package resolution to an approved repository or internal mirror.
- Run dependency scanning and signature or provenance verification where supported.
- If runtime installation is unavoidable, obtain explicit user consent, use an isolated virtual environment, enforce exact versions and hashes, and avoid importing packages until their integrity has been validated.
