T08 · Insecure Dependencies
- Location
SKILL.md:95- Finding
Unpinned Third-Party Dependencies Installed Outside an Isolated Environment
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:95andSKILL.md:125
Vulnerability Type: Unsafe dependency installation instructions
Risk Level: MediumVulnerable Code
At
SKILL.md:95:bash pip install matplotlib --break-system-packages -qAt
SKILL.md:125:bash pip install python-docx --break-system-packages -qTechnical Analysis
The Skill instructs users to install
matplotlibandpython-docxwithout pinned versions or cryptographic hashes. Package resolution therefore depends on mutable package-index state and the user's pip configuration at installation time.The
--break-system-packagesoption bypasses protections intended to prevent pip from modifying an externally managed Python installation. This can overwrite or conflict with operating-system-managed components and expands the consequences of a malicious or incompatible package installation.No lockfile, hash-verified requirements file, isolated virtual environment, or explicitly approved package index is provided. The named packages are consistent with the scripts' imports, and the project does not itself retrieve a remote payload. Nevertheless, the documented installation process creates a supply-chain exposure because downloaded package artifacts and their installation behavior are not reproducibly constrained.
Attack Path
- A user follows the prerequisite instructions in
SKILL.md. - Pip resolves an unspecified current version using the user's configured package index or mirror.
- An attacker compromises the configured index, mirror, package release, or dependency-resolution environment.
- Pip downloads and installs the attacker-controlled artifact.
- Package installation behavior executes with the privileges of the user running pip.
- The project scripts subsequently import the installed dependency, allowing malicious import-time behavior to execute again.
- Because `--break-system-pac ...[truncated 856 chars]
- A user follows the prerequisite instructions in
- Remediation
View remediation
Remediation Suggestions
- Remove
--break-system-packagesand install dependencies inside a dedicated virtual environment:bash python3 -m venv .venv . .venv/bin/activate python -m pip install --upgrade pip - Pin reviewed dependency versions in a requirements file:
text matplotlib==REVIEWED_VERSION python-docx==REVIEWED_VERSION - Generate and enforce cryptographic hashes:
bash python -m pip install --require-hashes -r requirements.txt - Include hashes for all transitive dependencies, preferably using a reproducible dependency-management tool.
- Use an explicitly approved package index or internal artifact repository rather than relying on arbitrary user-level pip configuration.
- Add automated dependency vulnerability, provenance, and license scanning to the release process.
- Run installation and document generation as a non-privileged account with minimal filesystem and network access.
- Document the supported Python and dependency versions and test updates before changing the pinned set.
- Remove
