T08 · Insecure Dependencies
- Location
run.sh:11- Finding
Unpinned Third-Party Package Installation During Runtime
- Content
View full analysis
/dev/null; then echo "Error: Rscript was not found" echo "Install R version 4.0 or later" echo "Download: https://cran.r-project.org/" exit 1 fi # Check whether ggplot2 is installed Rscript -e "if(!requireNamespace('ggplot2', quietly=TRUE)) install.packages('ggplot2')" 2>/dev/null ``` Related installation instructions also appear in: - `SKILL.md:85` - `SKILL.md:319-327` - `SKILL.md:335` - `skills/r-ggplot-quickplot/SKILL.md:194-210` ### Technical Analysis The runtime launcher automatically installs `ggplot2` if it is not already available. The installation does not specify an exact package version, trusted repository, integrity hash, signature, or lockfile. It therefore relies on the R repository configuration and dependency resolution state present on the executing system. R package installation can execute package installation hooks and native build operations with the privileges of the user running the Skill. If the configured repository, repository selection mechanism, package account, or upstream release is compromised, attacker-controlled installation code could run locally. The command also redirects standard error to `/dev/null`, concealing repository warnings, compilation errors, and other diagnostic information that could alert the user to an unexpected installation source or behavior. ### Attack Path 1. The target system does not already have `ggplot2` installed. 2. An attacker compromises or influences the R repository configured for that environment, or compromises a package or transitive dependency distributed through that repository. 3. The user invokes `run.sh`. 4. The launcher calls `install.packages('ggplot2' ...[truncated 665 chars]- Remediation
View remediation
