T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned Dependency Installation with System Package Protection Bypass
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 37-39
Vulnerability Type: Unpinned third-party package installation from a mutable package index
Risk Level: MediumVulnerable Code
bash pip install faster-whisper --break-system-packages 2>/dev/null || pip install faster-whisperThe dependency is also declared without a version constraint at line 18:
yaml - faster-whisper (pip install faster-whisper)Technical Analysis
The skill instructs the agent to install
faster-whisperwithout pinning an exact reviewed version or verifying package integrity with cryptographic hashes. Consequently, the code installed during each invocation depends on the mutable state of the configured Python package index and its dependency resolution graph.The
--break-system-packagesoption bypasses protections intended to prevent pip from modifying a system-managed Python environment. Redirecting standard error to/dev/nullalso conceals warnings and diagnostic information that could reveal repository, dependency-resolution, or environment-integrity problems.This installation process creates a supply-chain execution boundary: a compromised package release, compromised transitive dependency, maliciously configured package index, or future unsafe release could introduce attacker-controlled code. Installation artifacts and imported package code execute with the same operating-system privileges as the agent process.
Attack Path
- An attacker compromises a relevant package release, one of its transitive dependencies, or the Python package index configured in the execution environment.
- A user invokes the skill in an environment where
faster-whisperis not already installed. - The agent executes the documented unpinned
pip installcommand. - Pip resolves and downloads the currently available package and dependency versions without validating them against approved hashes.
- Malicio ...[truncated 1084 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
faster-whisperand every transitive dependency to reviewed, exact versions. - Generate a lock file containing cryptographic hashes and install with hash verification, such as
pip install --require-hashes -r requirements.txt. - Install dependencies in a dedicated virtual environment or immutable container rather than using
--break-system-packages. - Remove the fallback command that modifies the active environment without isolation.
- Do not suppress pip error output; retain installation diagnostics for auditing and incident investigation.
- Use an approved internal package mirror or explicitly trusted index with repository authentication and transport verification.
- Perform dependency vulnerability and provenance scanning before updating the pinned package set.
- Run transcription under a least-privileged account without access to unrelated credentials or sensitive files.
- Pin
