T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party Dependencies Are Installed and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–29 and 51–63
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
bash # Install OpenJudge pip install py-openjudge # Extra dependency for auto_arena (chart generation) pip install matplotlibThe installed package is subsequently executed:
bash # Run evaluation python -m cookbooks.auto_arena --config config.yaml --save # Use pre-generated queries python -m cookbooks.auto_arena --config config.yaml \ --queries_file queries.json --save # Start fresh, ignore checkpoint python -m cookbooks.auto_arena --config config.yaml --fresh --save # Re-run only pairwise evaluation with new judge model # (keeps queries, responses, and rubrics) python -m cookbooks.auto_arena --config config.yaml --rerun-judge --saveTechnical Analysis
The installation commands do not pin reviewed package versions, verify package hashes, or require a lockfile. Consequently, the code installed and executed can change over time without any modification to this Skill.
The supplied project contains only
SKILL.md; it does not include the referencedcookbooks.auto_arenaimplementation. The security-sensitive behavior of that module and its transitive dependencies therefore cannot be verified from the audited artifact. Package installation may execute build hooks, while later module invocation executes code obtained through the Python package supply chain.This is a supply-chain weakness rather than evidence that the currently published packages are malicious. Exploitation requires compromise or substitution of a package, one of its dependencies, or the configured package index.
Attack Path
- An attacker compromises a future release of
py-openjudge, one of its transitive dependencies, or a package source used by the victim. - The victim follows the documented
pip installcommands without a version or hash constraint. - Pip res ...[truncated 999 chars]
- An attacker compromises a future release of
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an explicitly reviewed version.
- Maintain a lockfile or hash-locked requirements file that includes transitive dependencies.
- Require cryptographic hash verification during installation, for example:
bash python -m pip install --require-hashes -r requirements.txt- Install packages only from a trusted, explicitly configured package index and disallow unexpected fallback indexes.
- Review dependency provenance and monitor pinned versions for security advisories.
- Execute the evaluation in an isolated virtual environment or container under a non-privileged account.
- Expose only the API credentials required for the current run and rotate them if dependency compromise is suspected.
- Where practical, include or vendor the security-relevant pipeline source so its behavior can be audited together with the Skill.
- Add reproducible installation instructions and integrity-verification procedures to
SKILL.md.
