T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Dependencies Create Supply-Chain Exposure
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1-3andreferences/setup-checklist.md:65
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
requirements.txt:1-3:text google-auth google-auth-httplib2 google-api-python-clientreferences/setup-checklist.md:65:bash pip3 install google-auth google-auth-httplib2 google-api-python-clientTechnical Analysis
The project installs third-party packages without exact version constraints or cryptographic hashes. Each installation therefore resolves the latest release available from the configured Python package index at installation time.
This prevents the audited source tree from defining a reproducible dependency set. A future compromised, malicious, or unexpectedly incompatible release could be installed without changes to this repository. This exposure is especially significant because these dependencies execute in a process that loads a service-account private key and creates credentials with Google Workspace domain-wide delegation.
No currently malicious package was identified in the reviewed files. The vulnerability is the absence of controls that ensure future installations use the reviewed dependency artifacts.
Attack Path
- An attacker compromises a maintainer account, distribution infrastructure, or release process for one of the unpinned dependencies.
- The attacker publishes a malicious release under the legitimate package name.
- An administrator follows the documented setup command or installs from
requirements.txt. - Package resolution selects and installs the malicious release because no exact version or hash is required.
- The malicious package code executes when imported by the Skill.
- It can attempt to read the service-account key, intercept delegated credentials, manipulate API requests, or exfiltrate Google Workspace data.
Impact Asses
...[truncated 621 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed exact version, for example with
package==version. - Generate a fully resolved lock file that also pins all transitive dependencies.
- Record SHA-256 hashes for every permitted distribution artifact.
- Install with hash verification, such as:
bash python3 -m pip install --require-hashes -r requirements.txt - Update the setup checklist to use the locked requirements file rather than installing unconstrained package names.
- Review dependency updates before refreshing the lock file and run automated vulnerability and provenance checks.
- Use a dedicated virtual environment and a trusted package index configuration.
- Run the Skill under a restricted operating-system account that can read only the required credential file and application files.
- Prefer short-lived or externally managed service-account credentials where operationally possible, reducing the impact of local key theft.
- Pin every direct dependency to a reviewed exact version, for example with
