T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Pre-release Dependency Installation
- Content
View full analysis
=1.4.0.a3,<2.0.0" ``` ### Technical Analysis The skill instructs users to install a third-party Python package with the `--pre` option and a broad version constraint. It does not pin an exact audited release or require package hashes. Consequently, later pre-release versions satisfying `>=1.4.0.a3,<2.0.0` may be installed without having been reviewed as part of this project. Python packages can execute code during installation or when their installed command-line entry points are invoked. The effective executable behavior therefore depends on mutable external package releases rather than solely on the audited skill files. No evidence establishes that the named package is currently malicious. The vulnerability is the unsafe dependency-installation policy and its exposure to package-repository, publisher-account, or upstream dependency compromise. ### Attack Path 1. An attacker compromises the package publisher, package repository, or an upstream dependency. 2. The attacker publishes a malicious pre-release version satisfying the documented version range. 3. A user follows the skill's installation command at a time when that release is selected by `pip`. 4. The malicious package is installed and its code executes during installation or subsequent `kmdr` invocation. 5. The code operates with the privileges of the user running `pip` or `kmdr`. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions, an attacker could access local files, Kmoe credentials, downloader configuration, downloaded content, environment variables, and network-accessible resources. The project does not direct users to ins ...[truncated 114 chars]- Remediation
View remediation
