subprocess module call
- Category
- Dangerous Code Execution
- Confidence
- 96% confidence
- Finding
The code automatically executes
pip installat runtime without explicit user approval. This expands the skill from local document conversion into network/package-management behavior and creates a supply-chain risk: a compromised package, poisoned index, or unexpected dependency resolution could cause arbitrary code execution in the agent environment.- Content
python try: print(f" [INFO] 将执行: pip install {pkg_name}(从 PyPI 下载,约数 MB,不会上传本机数据)") print(f" [依赖] 安装 {pkg_name} ...", end='', flush=True) result = subprocess.run( [sys.executable, '-m', 'pip', 'install', pkg_name, '-q'], capture_output=True, text=True, timeout=120, )
