T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:24- Finding
Execution of Mutable Third-Party Code and Unpinned Dependencies
- Content
View full analysis
- Remediation
View remediation
``` 2. Verify the checked-out commit against a documented expected SHA and, where available, verify a signed release or signed commit. 3. Audit and lock all Python dependencies to exact versions. Use a hash-locked requirements file and enforce verification: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Host the reviewed lockfile within the Skill package or provide its expected cryptographic digest so changes to upstream dependency declarations cannot silently alter installation behavior. 5. Review package build configurations and installation hooks before installation. Avoid dependencies sourced from mutable Git branches, arbitrary URLs, or untrusted package indexes. 6. Run the scraper inside an isolated, least-privilege environment such as a disposable container or virtual machine. Do not mount credential directories or unrelated host data, and restrict outbound network access to required destinations. 7. Use a dedicated non-administrative account and a fresh virtual environment. Do not expose API keys, browser profiles, SSH keys, cloud credentials, or sensitive environment variables to the process. 8. Document the exact reviewed repository revision, dependency set, verification procedure, and update-review process in `SKILL.md`. ]]>
