T08 · Insecure Dependencies
- Location
SKILL.md:65- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:65
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: MediumComplete vulnerable snippet:
markdown - pypinyin (pip install pypinyin) - Only required for Pinyin modeThe dependency is subsequently imported by
scripts/cn_slug_generator.py:101-110:python def pinyin_slug(text, separator='-'): """Convert text to a Pinyin slug.""" try: import pypinyin text = re.sub(r'[^\w\s\u4e00-\u9fff]', ' ', text) py = pypinyin.lazy_pinyin(text) words = [w for w in py if w.strip()] return separator.join(words) except ImportError: return textTechnical Analysis
The installation instruction uses
pip install pypinyinwithout a pinned version, integrity hashes, lockfile, or an explicitly trusted package index. Consequently, the exact code installed depends on package-index state at installation time rather than on a version reviewed with this project.Python packages may execute package-controlled build or installation logic during installation. They also execute top-level module code when imported. If the package distribution, a maintainer account, the configured package index, or the dependency resolution path is compromised, attacker-controlled code could execute when the user installs the dependency or invokes Pinyin mode.
This is a supply-chain weakness rather than evidence that the current
pypinyinpackage is malicious.Attack Path
- An attacker compromises a future
pypinyinrelease, its package-index publishing account, or a package index configured in the victim's environment. - A user follows the documented
pip install pypinyininstruction. - Because no version or hash is specified, pip resolves and downloads the attacker-controlled distribution.
- Malicious code executes during package build or i ...[truncated 776 chars]
- An attacker compromises a future
- Remediation
View remediation
Remediation Suggestions
-
Pin
pypinyinto a reviewed, exact version rather than installing the latest available release:text pypinyin==REVIEWED_VERSION -
Record cryptographic hashes in a requirements file and install with hash enforcement:
bash python3 -m pip install --require-hashes -r requirements.txt -
Generate and commit a lockfile using a dependency-management tool so direct and transitive dependency versions are reproducible.
-
Explicitly use a trusted package index and prevent unintended fallback to untrusted or organization-controlled indexes.
-
Review dependency updates before changing the pinned version, including package provenance, release history, and transitive dependencies.
-
Install and run the dependency in an isolated virtual environment under a non-privileged account. Do not invoke pip with root or administrator privileges.
-
Consider removing the optional dependency by using a reviewed in-project implementation if the additional supply-chain exposure is not justified.
-
