T08 · Insecure Dependencies
- Location
SKILL.md:477- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 477–480
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
bash pip install pandas numpyTechnical Analysis
The installation command retrieves mutable versions of
pandas,numpy, and their transitive dependencies from the package index configured forpip. No exact versions, cryptographic hashes, lock file, or trusted-index restrictions are specified.Consequently, two installations performed at different times may resolve to different dependency sets. If a package release or configured package index is compromised, or if an unexpected future release is selected, unreviewed code could be installed and executed with the user's privileges. The audit found no evidence that these package names are themselves malicious; the issue is the absence of dependency integrity and reproducibility controls.
Attack Path
- An attacker compromises a selected package release, a transitive dependency, or a package index used by the environment.
- A user follows the documented dependency installation command.
pipresolves the current mutable package versions from its configured index without validating them against project-approved hashes.- The compromised package is installed.
- Malicious code may execute during installation, import, or subsequent data-profiling operations.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user or automation account performing the installation or running the profiler. This could expose construction datasets and other files accessible to that account, alter generated reports, or compromise the associated Python environment. The scope is limited by the installing user's operating-system permissions and environmental isolation.
- Remediation
View remediation
Remediation Suggestions
- Move dependencies into a reviewed requirements or lock file and pin exact versions.
- Pin all transitive dependencies rather than only direct dependencies.
- Generate and verify cryptographic hashes, then install with a command such as:
bash python -m pip install --require-hashes -r requirements.txt- Use an approved package index or internal mirror and explicitly configure trusted sources.
- Run dependency vulnerability and provenance checks in CI before publishing updates.
- Install and execute the profiler in an isolated virtual environment or container with least-privilege filesystem access.
- Establish a controlled update process that reviews, tests, and regenerates dependency locks and hashes.
