T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned and Integrity-Unverified Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 6
Vulnerability Type: Supply-chain exposure through unverified and unpinned dependencies
Risk Level: MediumComplete Code Snippet:
bash pip install https://github.com/KittenML/KittenTTS/releases/download/0.8.1/kittentts-0.8.1-py3-none-any.whl soundfileTechnical Analysis
The installation command downloads and installs a Python wheel directly from an external GitHub release without verifying its cryptographic hash. Although the KittenTTS filename contains a version, the command does not ensure that the downloaded bytes match a reviewed artifact. The
soundfiledependency is not version-pinned and has no integrity constraint, so its selected version can vary over time.Python package installation and subsequent imports may execute third-party code with the privileges of the user running the command. If the GitHub release asset, upstream account, package index, dependency resolution process, or a transitive dependency is compromised, following the documented installation procedure could install attacker-controlled code.
The repository contains only
SKILL.md; therefore, the referenced CLI wrapper and dependency behavior could not be inspected. No evidence establishes that the currently referenced packages are malicious. The finding concerns the lack of reproducibility and integrity enforcement in the documented installation process.Attack Path
- An attacker compromises an upstream release asset, package publishing account, package-index distribution channel, or unresolved dependency.
- The attacker replaces or publishes a package artifact containing malicious installation or runtime code.
- A user follows the installation command in
SKILL.md. pipdownloads the artifact without checking it against a trusted hash and resolves the unpinnedsoundfilepackage and transitive dependencies.- Attacker-controlled code executes dur ...[truncated 583 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact reviewed version.
- Generate and maintain a lock file that fixes transitive dependency versions.
- Record trusted SHA-256 hashes for all package artifacts and install with hash enforcement, such as
pip install --require-hashes -r requirements.txt. - Download the KittenTTS wheel through a controlled build or artifact pipeline, verify its provenance and signature where available, and store an approved immutable copy in a trusted registry.
- Review package metadata, installation hooks, and transitive dependencies before approval.
- Perform installation and execution in an isolated virtual environment or sandbox with minimal filesystem and network privileges.
- Include the referenced
kittentts_cli.pyin the audited project, or provide a verifiable source and immutable revision, so its behavior can be reviewed.
