T08 · Insecure Dependencies
- Location
SKILL.md:87- Finding
Unpinned Third-Party Python Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:87-91; also documented inREADME.md:23-30andREADME.md:69-72
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:87-91:markdown ## Dependencies Requires `feedparser`: ```bash pip3 install feedparsertext Equivalent unpinned installation instructions also appear in `README.md`: ```bash pip3 install feedparserTechnical Analysis
The installation instructions retrieve
feedparserwithout specifying a reviewed version or validating an integrity hash. Consequently, the package resolved at installation time can differ from the version originally assessed with the Skill.Python packages may execute installation-time build logic and are later imported directly by
scripts/bbc_news.py. A compromised or unexpectedly changed package release could therefore execute code during installation or whenever the news script importsfeedparser.This is a supply-chain hardening issue. The audit found no evidence that the current
feedparserpackage or configured package name is malicious.Attack Path
- An attacker compromises the upstream package, its publisher account, or the package-distribution path.
- The attacker publishes a malicious release under the expected package name.
- A user follows the documented
pip3 install feedparserinstruction. - Pip resolves and downloads the uncontrolled release because no version or hash is pinned.
- Malicious code executes during package installation or when
scripts/bbc_news.pyimportsfeedparser.
Impact Assessment
Malicious dependency code would run with the privileges of the user invoking pip or the news script. It could access files, environment variables, credentials, and network resources available to that account, modify the Python environment, or execute additional commands. The scope does not inherently exceed ...[truncated 481 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin
feedparserto a specifically reviewed version in a requirements file, for example:text feedparser==REVIEWED_VERSION -
Generate and verify package hashes, then install with hash enforcement:
bash python3 -m pip install --require-hashes -r requirements.txt -
Use a dependency-locking workflow that records exact transitive dependency versions and hashes.
-
Recommend installation in a dedicated virtual environment rather than the system Python environment.
-
Avoid running pip as root or with unnecessary administrative privileges.
-
Periodically review and update the pinned dependency after checking release provenance, security advisories, and integrity information.
-
