T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
/webhook/transcript` ## Setup ```bash # Install Percept pip install getpercept ``` ``` ### Technical Analysis The Skill directs users to install `getpercept` from pip's default configured package index without specifying a reviewed version or an integrity hash. Consequently, the dependency resolved during installation may differ from the version that was reviewed when the Skill was published. Python packages can execute package-controlled code during build or installation. They also deliver executable modules and command-line entry points that users subsequently run. A compromised maintainer account, malicious package release, package-index compromise, or unexpected upstream update could therefore introduce arbitrary executable code. The Skill does link to an expected GitHub project, but it does not verify that the package downloaded by pip corresponds to a particular reviewed commit or release. ### Attack Path 1. An attacker compromises the package publisher, distribution channel, or a future upstream release. 2. The attacker publishes a modified `getpercept` package containing malicious installation or runtime code. 3. A user follows the Skill and runs `pip install getpercept`. 4. Pip resolves and installs the attacker-controlled release because no version or hash is specified. 5. Malicious code executes during installation or when the user invokes `percept start`. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the account performing the inst ...[truncated 315 chars]- Remediation
View remediation
