T08 · Insecure Dependencies
- Location
SKILL.md:295- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:295andREADME.md:9
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:295:bash pip3 install docling openpyxlREADME.md:9:bash pip3 install docling openpyxlTechnical Analysis
The installation instructions retrieve the latest available versions of
doclingandopenpyxlwithout version constraints, package hashes, a lock file, or an explicitly trusted package index. Consequently, the code installed by users can change after this Skill has been reviewed.Python packages can execute code during installation and whenever imported. The script imports both dependencies near startup, meaning a compromised or unexpectedly replaced package version could execute with the same privileges as the user running the Skill.
The repository does not itself contain a malicious dependency, and no direct dependency-confusion package name was identified. The vulnerability is the absence of controls that guarantee installation of the reviewed dependency artifacts.
Attack Path
- An upstream package release or one of its transitive dependencies is compromised.
- A user follows the documented command and installs the latest packages from the configured Python package index.
- The package manager downloads the compromised release because no version or hash constraint prevents it.
- Malicious code executes during package installation or when
extract.pyimports the dependency. - The malicious code operates with the privileges and data access of the installing or executing user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the current user's account. Depending on that user's privileges, the attacker could access local files, PDF source material, output data, Excel workbooks, environment variables, and credentials available to the process ...[truncated 126 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version, for example through a version-controlled requirements or lock file.
- Pin transitive dependencies as well, using a tool such as
pip-tools, Poetry, or an equivalent reproducible dependency manager. - Record and verify package hashes, then install with
pip install --require-hashes. - Configure an explicitly trusted package index rather than relying on an unspecified environment configuration.
- Run dependency vulnerability and provenance checks in CI.
- Periodically update dependencies through reviewed changes rather than automatically consuming the newest release.
- Install and execute the Skill in an isolated virtual environment or container with access limited to required input and output paths.
