T08 · Insecure Dependencies
- Location
scripts/generate_qr.py:8- Finding
Automatic Installation of an Unpinned Runtime Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_qr.py, lines 8-15
Vulnerability Type: Supply-chain risk caused by automatic installation of an unpinned dependency
Risk Level: HighVulnerable Code
python def ensure_qrcode(): try: import qrcode return qrcode except ImportError: import subprocess subprocess.check_call([sys.executable, "-m", "pip", "install", "qrcode[pil]", "-q"]) import qrcode return qrcodeThe behavior is also explicitly documented in
SKILL.md, lines 56-59:markdown ## Dependencies The script auto-installs `qrcode[pil]` via pip if missing. No manual setup needed.Technical Analysis
If the
qrcodemodule is unavailable, the script invokes pip and installsqrcode[pil]from the package source configured in the runtime environment. The requested dependency has no fixed version, integrity hash, lock file, or trusted repository constraint.Python package installation may execute package-controlled build or installation logic. Consequently, the effective code executed by the skill can change after review without any modification to the audited project. Relevant attack conditions include compromise of the legitimate package or its publishing account, unsafe package-index configuration, dependency resolution from an untrusted mirror, or malicious package substitution.
This is an insecure dependency-management pattern rather than evidence that the currently named package is malicious.
Attack Path
- The skill runs in an environment where
qrcodeis not installed. - An attacker compromises or influences a package source used by pip, such as the configured index, mirror, or resolved package release.
ensure_qrcode()catchesImportError.- The script automatically executes:
bash python -m pip install "qrcode[pil]" -q - Pip downloads and installs mutab ...[truncated 696 chars]
- The skill runs in an environment where
- Remediation
View remediation
Remediation Suggestions
- Remove automatic dependency installation from normal program execution.
- Declare dependencies in a dedicated project manifest and lock file.
- Pin
qrcodeand its transitive dependencies to reviewed versions. - Require package hashes during installation, such as through a hash-locked requirements file.
- Install dependencies during an explicit, controlled setup or build phase rather than when processing user requests.
- Restrict installation to an approved package index and validate repository configuration.
- Run dependency installation and QR generation inside a least-privileged virtual environment or sandbox.
- If the module is missing at runtime, fail safely with clear setup instructions instead of invoking pip automatically.
- Continuously scan pinned dependencies and update them through a reviewed release process.
