T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:27-30(also declared atSKILL.md:57and imported atpdf2md.py:12-16)
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumThe installation instructions and package metadata specify
pdfplumberwithout a fixed version or integrity hash:markdown ## Requirements ```bash pip install pdfplumbertext The dependency is also declared without a version constraint: ```yaml pypi: ["pdfplumber"]The application imports the package at runtime:
python try: import pdfplumber except ImportError: return "Error: pdfplumber not installed"Technical Analysis
Installing an unpinned dependency causes the resolved package code to vary over time. Consequently, the package executed by users may differ from the version that was reviewed during this audit. No evidence indicates that the current
pdfplumberpackage is malicious; the risk arises from the absence of version and integrity controls.If a future release, package repository account, distribution channel, or transitive dependency is compromised, installation may introduce attacker-controlled code. Python packages can execute installation-related logic, and imported package code runs with the privileges of the user invoking the converter. The dependency also directly processes potentially sensitive PDF documents.
Attack Path
- An attacker compromises the dependency's release process, repository account, package distribution channel, or a transitive dependency.
- The attacker publishes a malicious or backdoored version that satisfies the unrestricted package name
pdfplumber. - A user follows the documented
pip install pdfplumbercommand, or the Skill environment resolves the unversioned metadata declaration. - The package manager installs the attacker-controlled release.
- Malicious code executes during installation or when `pdfp ...[truncated 682 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
pdfplumberto a specifically reviewed version in both the installation instructions and Skill metadata. - Maintain a lock file that pins all transitive dependencies.
- Record and verify package hashes, such as through a hashed requirements file and
pip install --require-hashes. - Install packages exclusively from the official, trusted package index over authenticated TLS.
- Review dependency updates before changing pinned versions and use automated supply-chain vulnerability scanning.
- Run PDF conversion under a dedicated, least-privileged account or sandbox with access limited to the required input and output files.
- Pin
