T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:37
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumComplete Code Snippet:
markdown - Prowler installed (`pip install prowler`) for automated CIS benchmark checksTechnical Analysis
The prerequisite directs users to install
prowlerwithout specifying an exact version or verifying package integrity. As a result, the installed code depends on whichever release the configured Python package index resolves at installation time.Python package installation can execute package-controlled build and installation logic. If the package, one of its transitive dependencies, the package index, or the user's package-index configuration is compromised, following this instruction may execute unreviewed code. The absence of version and hash constraints also makes installations non-reproducible and prevents users from confirming that they received the version reviewed with this Skill.
This finding concerns the dependency installation guidance. The project itself does not contain evidence that the legitimate Prowler package is malicious.
Attack Path
- An attacker compromises a future Prowler release, one of its transitive dependencies, or a package source configured on the victim's system.
- A user follows the documented prerequisite and runs
pip install prowler. - Pip resolves the mutable, attacker-affected package release rather than a previously reviewed version.
- Package-controlled installation or runtime code executes under the identity of the user performing the installation.
- The malicious package gains access to resources available to that user, potentially including local files, environment variables, and AWS credentials used for the subsequent audit.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the account running pip or Prowler. In the intended ...[truncated 422 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Prowler to an exact, reviewed version, for example:
bash python3 -m pip install "prowler==<reviewed-version>" - Maintain a lock file containing exact versions of all transitive dependencies.
- Require cryptographic package hashes with pip's
--require-hashesoption. - Document and enforce a trusted Python package index rather than relying on arbitrary user configuration.
- Install the tool in a dedicated virtual environment or isolated container using an unprivileged account.
- Periodically review and deliberately update the pinned version after checking release provenance and vulnerability advisories.
- Pin Prowler to an exact, reviewed version, for example:
