T08 · Insecure Dependencies
- Location
SKILL.md:166- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 166-170
Vulnerability Type: Unpinned and unverifiable third-party package installation
Risk Level: MediumVulnerable Code
bash pip install qrcode[pil]Technical Analysis
The installation command retrieves the latest compatible
qrcodepackage and its optional Pillow dependency from the configured Python package index without pinning reviewed versions or verifying cryptographic hashes. No lockfile, hash constraints, or trusted-index requirements are provided.Consequently, the dependency code installed by this command may differ from the code reviewed when the Skill was published. If a dependency release, maintainer account, package-index account, or configured package source is compromised, following this instruction could install attacker-controlled package code. Python packages may execute build logic during installation and arbitrary code when imported or used.
This finding is limited to supply-chain exposure caused by the unpinned installation instruction. The audited file does not itself retrieve a remote executable payload, contain embedded malicious scripts, establish persistence, access credential files, or alter Agent instructions.
Attack Path
- An attacker compromises a relevant package release, maintainer account, dependency, or package source configured in the victim's environment.
- The attacker publishes a malicious version that remains compatible with the unconstrained
pip install qrcode[pil]requirement. - A user or Agent follows the installation instruction in
SKILL.md. pipresolves and downloads the attacker-controlled package or transitive dependency because no reviewed version or hash is enforced.- Malicious code executes during package build or installation, or later when the QR-generation examples import and use the package.
- The code runs with the privileges of the account performing the installation or executing the example ...[truncated 569 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a specifically reviewed version, for example through a version-controlled requirements file.
- Generate and enforce cryptographic hashes using a reproducible dependency-management workflow, such as
pip-compile --generate-hashesfollowed bypip install --require-hashes. - Pin and verify all transitive dependencies, including Pillow, rather than relying only on an unconstrained package extra.
- Install exclusively from an explicitly approved HTTPS package index or an internally controlled package mirror.
- Review package provenance, release history, maintainers, and known vulnerabilities before updating pinned versions.
- Perform dependency updates through a controlled review process with automated vulnerability and integrity scanning.
- Use an isolated virtual environment and avoid installation with root or other elevated privileges.
A hardened installation pattern is:
bash python -m pip install --require-hashes -r requirements.txtThe associated
requirements.txtshould contain reviewed, exact versions and hashes for every resolved dependency.
