T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Package Is Installed and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–19
Vulnerability Type: Unpinned external executable dependency
Risk Level: MediumVulnerable Code:
yaml install: - id: pip-navil kind: pip package: navil bins: [navil]Technical Analysis
The skill installs the third-party PyPI package
navilwithout specifying an exact version, package hash, signature, or locked transitive dependency set. It subsequently instructs the Agent to execute commands supplied by that package, includingnavil scan,navil pentest, andnavil report.The implementation of the dependency is not included in the audited artifact, so its runtime behavior and the claim that penetration testing produces no network traffic cannot be independently verified from the reviewed files. Although
checksums.jsonprotectsSKILL.mdandskill.json, it does not authenticate the external package or its transitive dependencies.This creates a supply-chain trust boundary in which the code ultimately executed can change after the skill itself has been reviewed. Exploitation would require compromise, replacement, or malicious publication of the dependency or one of its transitive dependencies; no such compromise was established during this audit.
Attack Path
- An attacker compromises the
navilpackage, its publishing account, the package distribution process, or a transitive dependency. - The attacker publishes a modified release containing malicious installation or runtime behavior.
- Because the skill does not pin an audited version and hash, installation may resolve to the attacker-controlled release.
- The skill installation process installs the modified package and exposes its
navilexecutable. - The Agent invokes
navil scan,navil pentest, ornavil reportas directed by the skill. - The malicious dependency executes with the privileges and environmental access of the install ...[truncated 777 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
navilto a specific version that has undergone security review rather than resolving the latest available release. - Require a verified cryptographic hash for the selected distribution, such as through a hash-locked requirements file and
pip --require-hashes. - Lock and review the complete transitive dependency graph using a reproducible lockfile.
- Verify package provenance through signed releases or trusted-publisher attestations where available.
- Prefer vendoring or otherwise making the dependency source available for review with the skill artifact.
- Install from an isolated environment using an explicitly configured trusted package index, and disable unexpected fallback indexes to reduce dependency-confusion exposure.
- Execute the auditing utility in a sandbox with read-only access to only the required configuration paths, minimal environment variables, no unnecessary credentials, and network access disabled unless a documented function requires it.
- Extend integrity metadata to cover the exact external artifacts and dependency versions used at installation time.
- Pin
