T08 · Insecure Dependencies
- Location
install.sh:18- Finding
Unpinned dependencies are installed into user or system Python environments
- Content
View full analysis
/dev/null; then echo "✓ Dependencies installed (--user)" elif pip3 install --break-system-packages garminconnect fitparse gpxpy 2>/dev/null; then echo "✓ Dependencies installed (--break-system-packages)" elif pip3 install garminconnect fitparse gpxpy 2>/dev/null; then echo "✓ Dependencies installed (system-wide)" else echo "❌ Failed to install Python dependencies" echo " Try manually: pip3 install --user garminconnect fitparse gpxpy" exit 1 fi ``` Related unpinned installation instructions also appear in: - `SKILL.md:7` - `SKILL.md:25-31` - `README.md:23-28` - `references/mcp_setup.md:21-32` ### Technical Analysis The installer retrieves the latest available releases of three executable Python packages without version constraints, hashes, or a lock file. The effective code installed can therefore change after the Skill itself has been reviewed. The `--break-system-packages` fallback bypasses Python's externally managed environment protection. The final fallback may modify a system-wide Python environment, depending on the invoking user's privileges and local `pip` configuration. These installation scopes are broader than necessary for the Skill, which can operate from an isolated virtual environment. Suppressing standard error with `2>/dev/null` also hides package verification, dependency-conflict, and environment-integrity warnings that could be security-relevant. ### Attack Path 1. An attacker compromises one of the named PyPI packages, one of its transitive dependencies, or the publisher account. 2. The attacker publishes a malicious version. 3. A user runs `install. ...[truncated 732 chars]- Remediation
View remediation
