T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party Dependencies Permit Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:25,SKILL.md:30,SKILL.md:35, andSKILL.md:104
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: MediumAffected code snippets:
SKILL.md:25bash pipx install 'markitdown[all]'SKILL.md:30bash pip install 'markitdown[all]'SKILL.md:35bash pip install 'markitdown[pdf,docx,pptx]'SKILL.md:104bash pip install markitdown-mcpTechnical Analysis
The documented installation commands resolve mutable, unpinned versions of
markitdown,markitdown-mcp, and their transitive dependencies from the configured package index. The[all]extra substantially expands the dependency tree and therefore the supply-chain attack surface.The project does not provide a lockfile, constraints file, package hashes, exact version requirements, or index restrictions. Consequently, the code installed by these commands can change after this Skill has been reviewed. A malicious or compromised future package release, compromised transitive dependency, dependency-confusion package from an untrusted configured index, or unexpected upstream change could introduce arbitrary code into the user's environment.
The referenced package names and upstream links appear legitimate, and the audited project contains no evidence that the current packages are malicious. The risk arises from executing future dependency versions without reproducibility or integrity verification.
Attack Path
- An attacker compromises a relevant package or transitive dependency, publishes a malicious future release, or introduces a higher-priority package through an untrusted package index.
- A user follows one of the installation commands in
SKILL.md. piporpipxresolves the latest compatible package graph because no exact versions, hashes, or trusted-index restrictions are specified.- The package ma ...[truncated 1067 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed exact version, including
markitdownandmarkitdown-mcp. - Generate and commit a reproducible lockfile or constraints file that also constrains transitive dependencies.
- Require cryptographic hashes for downloaded distributions, such as through a requirements file used with
pip install --require-hashes. - Install only the format-specific extras required by the deployment rather than
[all]. - Restrict installation to an explicitly trusted package index and prevent unintended fallback to user-controlled or internal indexes.
- Review package provenance, release signatures where available, maintainers, and dependency changes before updating pinned versions.
- Perform installation and conversion in a dedicated, non-privileged virtual environment or container with minimal filesystem and network access.
- Add automated dependency auditing and update pins only through a reviewed change process.
- Pin and verify
markitdown-mcpindependently because it exposes an integration service and may have a dependency graph distinct from the core converter.
A hardened installation flow should use reviewed exact versions and a hash-locked requirements file rather than resolving mutable latest releases directly from the documentation.
- Pin every direct dependency to a reviewed exact version, including
