T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Third-Party Shodan Dependency
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:17-20README.md:55-61README.md:117-123
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium
Classification: T08: Insecure DependenciesVulnerable Code
SKILL.md:17-20:markdown 1. **Install dependencies**: ```bash pip install shodan ```README.md:55-61:markdown #### 2. Install Dependencies Install the required Python library: ```bash pip3 install shodantext `README.md:117-123`: ```markdown #### 2. 安装依赖 安装必要的 Python 库: ```bash pip3 install shodantext ### Technical Analysis The installation instructions retrieve the latest available `shodan` package and its transitive dependencies without specifying reviewed versions or validating package hashes. The project does not provide a version-pinned requirements file or lockfile. Consequently, the code installed by users can differ from the code available when this skill was audited. If the upstream package, one of its dependencies, a maintainer account, or package-index resolution is compromised, installation may introduce arbitrary code into the skill's runtime environment. This is a supply-chain weakness rather than evidence that the current `shodan` package is malicious. The audited skill itself contains no remote payload loader, persistence mechanism, obfuscated payload, or unrelated credential-exfiltration logic. ### Attack Path 1. An attacker compromises a future release of `shodan`, one of its transitive dependencies, or an associated package-publishing account. 2. A user follows the documented `pip install shodan` or `pip3 install shodan` instruction. 3. The package manager resolves and installs the attacker-controlled release because no exact versions or integrity hashes are enforced. 4. Malicious installation hooks or imported runtime code execute with the privileges ...[truncated 941 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin
shodanand every transitive dependency to reviewed versions in a dedicated requirements file. -
Generate and verify cryptographic hashes for all distributions. For example:
text shodan==REVIEWED_VERSION --hash=sha256:VERIFIED_HASH -
Install dependencies with hash enforcement:
bash python3 -m pip install --require-hashes -r requirements.txt -
Generate the fully resolved, hash-locked file using a dependency-locking tool such as
pip-compile --generate-hashes, then commit it to the project. -
Install the dependencies in an isolated virtual environment rather than the user's global Python environment.
-
Use a trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.
-
Add automated dependency scanning and a controlled review process before updating locked versions.
-
Update both
SKILL.mdandREADME.mdso every installation example uses the same locked dependency workflow.
-
