T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unpinned Third-Party Python Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58-62
Vulnerability Type: Unpinned dependency installation
Risk Level: Mediumbash 2. 执行 pip 安装命令 ```bash pip install rpi-hardware-pwm ```Technical Analysis
The installation command retrieves
rpi-hardware-pwmwithout specifying a reviewed version or verifying an integrity hash. Consequently, the package version and effective code installed can change over time without any corresponding change to this skill.Python package installation can execute package build hooks and subsequently exposes the installed package to execution when it is imported. If the package distribution or its publishing account is compromised, a modified release could execute attacker-controlled code with the privileges of the user running
pipor the servo-control program. The absence of a lock file, hashes, and an explicitly documented trusted source also makes installations non-reproducible.Attack Path
- An attacker compromises the upstream package, its publisher account, or its distribution process.
- The attacker publishes a malicious release under the expected package name.
- A user follows the skill instruction and runs
pip install rpi-hardware-pwm. - Because no version or hash is enforced,
pipresolves and downloads the attacker-controlled release. - Malicious code may execute through installation hooks or when the installed package is imported by the PWM example.
- The payload obtains the permissions available to the invoking user and can access resources available within that user's environment.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation or running the imported package. This may expose that user's files, environment variables, network access, and hardware interfaces for which the user has permission. The documented command ...[truncated 106 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
rpi-hardware-pwmto a specifically reviewed version. - Maintain the dependency in a lock or requirements file containing cryptographic hashes.
- Install with hash enforcement, such as
pip install --require-hashes -r requirements.txt. - Document the expected official package index and upstream source repository.
- Review direct and transitive dependencies before updating the pinned version.
- Prefer binary wheels from a trusted source where appropriate, and prevent unexpected source builds.
- Continue installing into an isolated virtual environment with the least-privileged user required for operation.
- Pin
