T08 · Insecure Dependencies
- Location
scripts/chinese_converter.py:12- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/chinese_converter.py:12-17; additionally documented inSKILL.md:19
Vulnerability Type: Unpinned package installation from a mutable package index
Risk Level: MediumVulnerable Code
python try: from opencc import OpenCC return OpenCC except ImportError: print("Error: the opencc library is not installed") print("Run: pip install opencc-python-reimplemented")The installation command communicated by the script is:
shell pip install opencc-python-reimplementedSKILL.md:19also declaresopencc-python-reimplementedas an external dependency without specifying a version or integrity hash.Technical Analysis
The project instructs users to install
opencc-python-reimplementedfrom the configured Python package index without pinning a reviewed version or verifying an artifact hash. Package-index content is mutable: a later release, compromised publisher account, compromised index, or maliciously configured mirror could supply code different from what was reviewed during this audit.Python package installation may execute package-controlled build backend logic. The installed package is subsequently imported as
opencc, causing its runtime initialization code to execute whenever conversion is requested. There is no evidence that the currently published dependency is malicious; the confirmed issue is the absence of version and integrity controls around executable third-party code.Attack Path
- An attacker compromises the dependency publisher, package index, or package mirror, or causes a malicious future release to be selected.
- A user follows the displayed
pip install opencc-python-reimplementedinstruction. pipresolves the latest acceptable release because no exact version or hash is required.- Malicious build logic may execute during installation.
- Malicious runtime logic may also exec ...[truncated 766 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an explicitly reviewed version, for example through a locked requirements file:
text opencc-python-reimplemented==REVIEWED_VERSION - Record and enforce trusted artifact hashes with
pip --require-hashes. - Generate and commit a reproducible lock file containing all transitive dependency versions and hashes.
- Update both
SKILL.mdand the runtime error message to reference the locked installation procedure rather than an unconstrainedpip installcommand. - Recommend installation inside a dedicated virtual environment under a non-administrative account.
- Review dependency updates before changing the pinned version, including package provenance, release history, ownership changes, and artifact integrity.
- Where feasible, use an internally controlled package mirror containing only reviewed artifacts.
- Pin the dependency to an explicitly reviewed version, for example through a locked requirements file:
