T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25-27
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
bash # Install pip install glmocrTechnical Analysis
The installation instruction retrieves the latest available
glmocrpackage without specifying a reviewed version or verifying an integrity hash. Consequently, the code installed when a user follows this instruction can differ from the code that existed when the Skill was audited.Python packages and their transitive dependencies can run code during installation and import. If the package publisher account, package index, release process, or a transitive dependency is compromised, a malicious package version could execute code in the user's environment. The instruction also does not identify an approved package index or provide a lock file containing hashes.
Attack Path
- An attacker compromises the package publisher, distribution channel, or a transitive dependency.
- The attacker publishes a malicious release under the package name resolved by
pip. - A user or agent follows the documented
pip install glmocrinstruction. pipdownloads the attacker-controlled release because no version or hash is constrained.- Malicious installation-time or runtime code executes with the privileges of the user running
pip. - That code may access files, environment variables, credentials, and documents available to the process.
Impact Assessment
Successful exploitation can result in arbitrary code execution under the installing user's privileges. The affected scope may include readable local files, OCR input documents, the
ZHIPU_API_KEYenvironment variable, and other credentials accessible to that user. If installation is performed in a privileged environment, the impact increases accordingly.- Remediation
View remediation
Remediation Suggestions
- Pin
glmocrto a specifically reviewed version rather than installing the latest release. - Use a hash-locked requirements file, for example with
--require-hashes. - Lock and audit all transitive dependencies.
- Explicitly identify the trusted package index and disable unexpected supplemental indexes.
- Install the package in an isolated, least-privileged virtual environment.
- Add a controlled update process that requires security review before changing the pinned version.
- Pin
