T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Remote Repository Installation Enables Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type:T08: Insecure Dependencies
Risk Level: HighVulnerable Code
sh git clone https://github.com/Coyote-git/gifhorse.git ~/gifhorse && cd ~/gifhorse && python3 -m venv venv && source venv/bin/activate && pip install -e .Technical Analysis
The installation command clones the current state of a remote Git repository without pinning an audited commit, signed tag, release artifact, or cryptographic checksum. It then runs
pip install -e ., which installs the retrieved project in editable mode and may execute package build or installation logic.Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. The remote implementation and its transitive Python dependencies are not included in the audited artifact, so their behavior cannot be verified from this project. Compromise of the upstream account, repository, or dependency chain could turn the documented installation process into an arbitrary-code-execution channel.
Although network-dependent subtitle retrieval and optional iMessage delivery are disclosed as part of the Skill's functionality, the unpinned installation source is not necessary to provide those features and exceeds a safely reproducible trust boundary.
Attack Path
- An attacker compromises the upstream repository, its maintainer account, or a dependency referenced by the project.
- The attacker adds malicious package installation or runtime logic to the branch cloned by default.
- A user invokes the Skill's documented installation command.
- Git retrieves the attacker-controlled repository state because no immutable revision is specified.
pip install -e .processes and installs the retrieved package, potentially executing malicious build or installation logic.- The installed
gifhorsecommand can subsequently ...[truncated 860 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a specific, reviewed Git commit or immutable signed release rather than the repository's mutable default branch.
- Verify the release artifact using a cryptographic checksum or a trusted signature before installation.
- Replace editable installation with installation from an immutable, versioned artifact intended for end users.
- Lock all direct and transitive Python dependencies to reviewed versions and verify them with hashes.
- Prefer vendoring the required implementation in the Skill package when feasible so the executed code can be audited together with the Skill.
- Document the exact external services contacted for subtitle retrieval, the metadata transmitted, and applicable privacy implications.
- Require explicit user confirmation before sending generated media through iMessage or transmitting media-derived information to external services.
