T08 · Insecure Dependencies
- Location
SKILL.md:471- Finding
Unverified Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 471–472
Vulnerability Type: Supply-chain risk from installing unaudited external dependencies
Risk Level: MediumVulnerable Code
bash # Install dependencies python3 -m pip install -r ~/.codex/arch-compiler/tools/requirements.txtTechnical Analysis
The skill instructs the agent to install Python packages from a requirements file in a separately installed compiler repository. That requirements file is not included in the audited project, so its package names, sources, version constraints, and integrity controls could not be verified.
The command does not visibly enforce exact versions, package hashes, a trusted package index, or binary-only installation. Depending on the external requirements file and pip configuration, installation can retrieve mutable or compromised distributions and execute package build or installation logic with the privileges of the agent's operating-system account.
This is a supply-chain trust-boundary weakness. The documented compiler repository, its requirements file, the configured Python package index, and all resolved transitive dependencies must be trusted even though they are outside the reviewed artifact.
Attack Path
- An attacker compromises the separately installed architecture-compiler repository, alters its
tools/requirements.txt, publishes a malicious dependency version, or exploits dependency confusion through an unsafe package source. - An agent follows the skill instructions and executes:
bash python3 -m pip install -r ~/.codex/arch-compiler/tools/requirements.txt - Pip resolves and downloads the attacker-controlled package or compromised release.
- Malicious build or installation code executes under the agent user's account.
- The payload can access files, credentials, environment variables, and repositories available to that account and can perform further actions within those privileges.
Impact Ass
...[truncated 594 chars]
- An attacker compromises the separately installed architecture-compiler repository, alters its
- Remediation
View remediation
Remediation Suggestions
- Include an audited dependency lock file with the skill or pin the compiler to a reviewed immutable release.
- Pin every direct and transitive dependency to an exact version.
- Record cryptographic hashes and install with hash verification:
bash python3 -m pip install --require-hashes -r requirements.lock - Explicitly configure an approved package index and disable untrusted supplemental indexes to reduce dependency-confusion exposure.
- Verify the compiler checkout against a trusted commit hash or signed release before reading its requirements.
- Install dependencies in a dedicated virtual environment or disposable, least-privilege container rather than the user's global Python environment.
- Prefer prebuilt, verified wheels where feasible to reduce arbitrary build-time execution.
- Add automated dependency scanning and periodic lock-file review before approving dependency updates.
- Document that installation must not be run with
sudoor an administrative account.
