T08 · Insecure Dependencies
- Location
SKILL.md:41- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 41
Vulnerability Type: Unpinned package installation without integrity verification
Risk Level: MediumVulnerable Code Snippet:
bash pip install tencentcloud-sdk-pythonTechnical Analysis
The documented installation command retrieves the currently available version of
tencentcloud-sdk-pythonwithout an exact version constraint, cryptographic hash verification, or a dependency lockfile. Consequently, the code installed by users can differ from the version originally reviewed.This creates a supply-chain risk if the package, one of its transitive dependencies, a package-index account, or the distribution channel is compromised. Malicious package code could execute during installation or when
scripts/main.pyimports the Tencent Cloud SDK. The audit found no evidence that the package name itself is typosquatted or currently malicious; the finding concerns the absence of reproducible and integrity-verified dependency controls.Attack Path
- An attacker compromises the package publisher, package-index account, release pipeline, or a transitive dependency.
- The attacker publishes a malicious release under a version accepted by the unrestricted installation command.
- A user follows the Skill documentation and runs
pip install tencentcloud-sdk-python. - The package manager downloads and installs the attacker-controlled release.
- Malicious code executes during package installation or when
scripts/main.pyimports the SDK. - That code can access data available to the Python process, potentially including Tencent Cloud credentials, submitted facial media, accessible local files, and network resources.
Impact Assessment
Exploitation would run code with the privileges of the user or service account installing or invoking the Skill. Potential impact includes theft of
TENCENTCLOUD_SECRET_IDandTENCENTCLOUD_SECRET_KEY, una ...[truncated 450 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
tencentcloud-sdk-pythonto an exact, reviewed version rather than installing the latest available release. - Record direct and transitive dependencies in a lockfile or hash-locked requirements file.
- Require cryptographic hash verification during installation, for example with
pip install --require-hashes -r requirements.txt. - Generate hashes only from packages obtained through the official, trusted package index and verify the package publisher and release provenance.
- Periodically review and deliberately update the pinned version after security testing instead of accepting upgrades automatically.
- Install and execute the Skill in an isolated virtual environment or container under a minimally privileged service account.
- Limit the associated Tencent Cloud credentials to only the API permissions required for
DetectAIFakeFaces, and avoid exposing unrelated secrets to the process.
- Pin
