T08 · Insecure Dependencies
- Location
SKILL.md:99- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 99
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code Snippet
markdown Script dependencies: `pip install python-docx olefile` (`gongwen_checklist.py` needs no extra packages).Technical Analysis
The skill instructs users or agents to install
python-docxandolefilewithout specifying reviewed versions or cryptographic hashes. Consequently, installation results depend on mutable package-index state at the time the command is run.If an upstream package, maintainer account, release process, or configured package index is compromised,
pipcould retrieve a malicious or unexpectedly changed release. Python package installation may execute package build logic, while malicious installed modules could execute later when imported by the bundled scripts.No evidence indicates that the named packages are currently malicious. The risk arises from the unsafe, non-reproducible dependency installation practice.
Attack Path
- An attacker compromises an upstream dependency release, its publishing account, or a package index used by the environment.
- A user or agent follows the instruction in
SKILL.mdand runs:bash pip install python-docx olefile - Because no version or hash is pinned,
pipresolves the attacker-controlled or compromised release. - Malicious installation logic may run during installation, or malicious module code may run when
format_gongwen_docx.pyorread_doc_text.pyimports the package. - The payload executes with the privileges of the user or automation account performing the installation or running the script.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing or script-running account. The resulting scope may include access to documents processed by the skill, files readable or writable by that account, environment variables, and other ...[truncated 136 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the free-form installation command with a reviewed lock file containing exact versions:
text python-docx==<reviewed-version> olefile==<reviewed-version> - Record SHA-256 hashes for all direct and transitive artifacts and require verification:
bash python -m pip install --require-hashes -r requirements.txt - Generate and review the lock file in a controlled build process, including all transitive dependencies.
- Use an approved package index or internal artifact repository rather than an arbitrary environment-configured source.
- Install dependencies inside an isolated virtual environment or container under a non-privileged account.
- Periodically scan and deliberately update pinned dependencies after reviewing advisories and release provenance.
- Document the expected Python and
pipversions to improve reproducibility.
- Replace the free-form installation command with a reviewed lock file containing exact versions:
