T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unbounded Third-Party Dependency Installation
- Content
View full analysis
=1.1.2 ``` `SKILL.md:71-75`: ```markdown If `python-docx` is missing, install dependencies first: ```bash python3 -m pip install -r requirements.txt ``` ``` ### Technical Analysis The documented installation procedure directs the user or Agent to install a third-party package from the configured Python package index. The constraint `python-docx>=1.1.2` permits pip to select any current or future release satisfying the minimum version. No exact version, lock file, upper version bound, package hash, or transitive dependency constraints are supplied. Consequently, the dependency graph installed at execution time may differ from the dependency graph reviewed during this audit. The currently declared package is a legitimate public dependency, and the project contains no evidence that it is presently malicious. The security weakness is that a future compromised, malicious, or unexpectedly incompatible release could be selected automatically. Package installation or subsequent import may then execute code under the privileges of the user running pip or the resume generator. ### Attack Path 1. An Agent follows the setup instructions in `SKILL.md`. 2. The Agent executes `python3 -m pip install -r requirements.txt`. 3. pip queries the configured package index and resolves the newest release satisfying `python-docx>=1.1.2`, together with its transitive dependencies. 4. If a permitted future release or one of its resolved dependencies has been compromised, pip installs the affected component without integrity verification. 5. Malicious code may execute during installation or when `generate_resume.py` imports the package. 6. The payload runs with the permissions of the invoking user and can access ...[truncated 633 chars]- Remediation
View remediation
``` 2. Generate and commit a lock file that pins all transitive dependencies rather than only the direct dependency. 3. Record cryptographic hashes for every resolved distribution and enforce them during installation: ```bash python3 -m pip install --require-hashes -r requirements.lock ``` 4. Build the lock file from a trusted package index in a controlled environment. Avoid untrusted extra indexes and dependency sources. 5. Review dependency updates explicitly instead of accepting them automatically. Use automated vulnerability and provenance scanning before updating pinned versions. 6. Prefer an isolated virtual environment or container with least-privilege filesystem and network access when installing dependencies and processing candidate data. 7. Update `SKILL.md` so its installation example uses the reviewed lock file and hash verification rather than the unbounded `requirements.txt`. ]]>
