T08 · Insecure Dependencies
- Location
SKILL.md:44- Finding
Unpinned and Unnecessary Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 44–51; duplicated inkit.md, lines 44–51
Vulnerability Type: Unverified third-party package and mutable model installation
Risk Level: MediumVulnerable Code
bash # Install dependencies pip install ollama # Start Ollama server ollama serve # Pull embedding model ollama pull nomic-embed-text ollama pull gemma3:4bTechnical Analysis
The installation instructions fetch an unpinned Python package and mutable model artifacts without version constraints, checksums, signatures, or digest verification. Consequently, the effective installed components may change after the Skill has been audited.
The
ollamaPython package is also unnecessary for the current implementation:src/mordred_v4.1.pydoes not import it and instead accesses the local Ollama service throughurllib.request. Installing an unused package needlessly expands the supply-chain attack surface.This finding does not establish that the named package or models are currently malicious. The risk arises from allowing future or compromised upstream artifacts to be installed without integrity controls.
Attack Path
- An attacker compromises an upstream package or model distribution channel, or a mutable artifact is replaced with an unsafe release.
- A user follows the documented installation commands.
pipretrieves the current unpinned package, while Ollama retrieves the current model artifacts.- Malicious package installation behavior could execute under the installing user's privileges, or a manipulated model could produce attacker-influenced classifications.
- Any resulting access is bounded by the privileges of the user or environment performing the installation and running the affected component.
Impact Assessment
A compromised Python dependency could execute code with the installing user's privileges, potentially affecting files, credentials, processes, and network resources accessible t ...[truncated 364 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
pip install ollama, because the current Python implementation does not use that package. - Document installation of the Ollama runtime through an authenticated and verified official distribution channel.
- Pin every required dependency and model to an immutable version or digest.
- Verify checksums or cryptographic signatures before installation where the distribution mechanism supports them.
- Record approved artifact hashes in the repository and fail installation when verification does not succeed.
- Use a locked dependency manifest and automated dependency scanning if a Python client dependency is introduced later.
- Run model services with least privilege and restrict their filesystem and network access.
- Apply the same corrected instructions to
kit.md, which duplicates the affected commands.
- Remove
