T08 · Insecure Dependencies
- Location
scripts/gas-fee.py:21- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gas-fee.py:21
Vulnerability Type: Unpinned package installation
Risk Level: MediumVulnerable Code:
text pip install web3Technical Analysis
The script directs users to install the latest available release of the third-party
web3package without specifying an audited version, verifying package hashes, or providing a dependency lock file. The installed package and its transitive dependencies can therefore change independently of the reviewed Skill.Although the script does not automatically execute the installation command, users following its displayed remediation instruction may install code that was not part of the audit. If the package index, a future package release, or a transitive dependency is compromised, malicious installation or import-time code could execute in the user's environment.
Attack Path
- A user runs
scripts/gas-fee.pyin an environment whereweb3is unavailable. - The script displays an instruction to run
pip install web3. - The user executes that command without a pinned version or hash verification.
- The package manager resolves the current
web3release and its transitive dependencies from the configured package index. - If any resolved package or package source has been compromised, attacker-controlled code executes during installation or when the script imports the package.
- The malicious code runs with the permissions of the user performing the installation or invoking the script.
Impact Assessment
A compromised dependency could execute arbitrary code with the installing user's privileges. Depending on those privileges and the host environment, the resulting access could include reading or modifying user files, accessing environment variables and locally available credentials, making network requests, or altering the Python environment. The Skill itself does not request elevated privileges ...[truncated 93 chars]
- A user runs
- Remediation
View remediation
Remediation Suggestions
- Add a reviewed dependency manifest that pins
web3and all transitive dependencies to exact versions. - Generate and verify cryptographic hashes for dependency artifacts, such as by using a hash-locked requirements file and
pip install --require-hashes. - Replace the unpinned installation instruction with a command referencing the reviewed dependency manifest.
- Recommend installation inside a dedicated virtual environment rather than the system Python environment.
- Use automated dependency scanning and controlled update reviews before changing pinned versions.
- Document the trusted package index and avoid unverified alternative indexes or direct package URLs.
- Add a reviewed dependency manifest that pins
