T08 · Insecure Dependencies
- Location
scripts/install.sh:54- Finding
Unpinned Dependencies Installed from a Third-Party Package Mirror
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install.sh, lines 54-60
Vulnerability Type: Unpinned third-party dependencies and unsafe supply-chain trust
Risk Level: MediumVulnerable Code
bash # 升级 pip echo "" echo "升级 pip..." pip install --upgrade pip -i https://pypi.tuna.tsinghua.edu.cn/simple # 安装依赖 echo "" echo "安装 FunASR 及依赖(这需要几分钟)..." pip install funasr modelscope huggingface_hub torch torchaudio \ -i https://pypi.tuna.tsinghua.edu.cn/simpleTechnical Analysis
The installer downloads and installs the latest available versions of
pip,funasr,modelscope,huggingface_hub,torch,torchaudio, and their transitive dependencies from a third-party PyPI mirror. It does not enforce package versions, artifact hashes, or a reviewed lock file.Python package installation may execute package build and installation logic. Installed packages may also execute code when imported. Consequently, the effective code executed by this Skill can change without any modification to the audited repository.
The dependency and model downloads are legitimate requirements of the declared transcription functionality. However, unrestricted upgrades, unpinned dependency resolution, and reliance on a third-party mirror create avoidable supply-chain exposure beyond the minimum trust necessary.
Attack Path
- An attacker compromises the configured package mirror, an upstream package release, or a transitive dependency.
- The attacker publishes or substitutes a malicious package version that satisfies the unconstrained installation request.
- A user or autonomous agent runs
scripts/install.sh. pipretrieves and installs the attacker-controlled artifact.- Malicious code executes during package installation, verification import, or later transcription.
- The code operates with the permissions and data access of the account running the Skill.
Impact Assessment
Su ...[truncated 704 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed, exact version.
- Generate and commit a lock file containing resolved transitive dependencies.
- Use hashes for every permitted artifact and install with
pip --require-hashes. - Pin
pipitself instead of using an unrestricted--upgrade. - Prefer the official PyPI index, or clearly require explicit user trust and consent before using the configured mirror.
- Separate dependency installation from transcription and require clear user approval before initiating network downloads.
- Pin model downloads to immutable revisions and verify checksums where supported.
- Periodically review and update dependency pins through a controlled security-update process.
- Run installation and transcription in a sandbox with restricted filesystem and network access when processing sensitive recordings.
