T08 · Insecure Dependencies
- Location
scripts/requirements.txt:2- Finding
Unpinned and Unverified Perfetto Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
scripts/requirements.txt:2,SKILL.md:139-140,151, andreference.md:53,63-64
Vulnerability Type: Supply-chain risk caused by mutable dependencies and an unverified executable download
Risk Level: MediumVulnerable Code
scripts/requirements.txt:2:text perfetto>=0.0.0SKILL.md:139-140:bash curl -LO https://get.perfetto.dev/trace_processor chmod +x ./trace_processorSKILL.md:151:bash # 依赖: pip install perfetto(或 pip install -r perfetto-analyse/scripts/requirements.txt)reference.md:53:bash pip install -r perfetto-analyse/scripts/requirements.txt # 或 pip install perfettoreference.md:63-64:bash curl -LO https://get.perfetto.dev/trace_processor && chmod +x ./trace_processor ./trace_processor trace.pftraceTechnical Analysis
The requirement
perfetto>=0.0.0has no upper bound, exact version, or integrity hash. Consequently, the dependency resolved during installation may differ from the version assessed during this audit. A compromised, malicious, or unexpectedly incompatible future release would be accepted automatically.The documented alternative downloads
trace_processorfrom a mutable URL, makes it executable, and instructs the user to run it without verifying a release version, cryptographic signature, or checksum. HTTPS protects data in transit but does not establish that the retrieved artifact is the exact artifact previously reviewed.The referenced package and download domain are consistent with the Skill's declared Perfetto functionality. No evidence indicates that the current project intentionally distributes a malicious payload. The vulnerability is the absence of controls ensuring that future installed artifacts remain identical to audited artifacts.
Attack Path
- An attacker compromises the upstream package publication process, download ...[truncated 1246 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the open-ended requirement with an exact, reviewed version:
text perfetto==<reviewed-version> -
Generate a lock file containing cryptographic hashes and install it with hash enforcement:
bash python -m pip install --require-hashes -r requirements.lock -
Pin
trace_processorto a specific official release rather than a mutable latest-download URL. -
Publish the expected SHA-256 digest in the project and verify it before granting execute permission:
bash echo "<expected-sha256> trace_processor" | sha256sum --check - chmod +x trace_processor -
Prefer signature verification when the upstream project provides signed releases. Document the trusted signing key and fail closed if verification is unsuccessful.
-
Review and update pinned artifacts through a controlled dependency-update process that includes provenance validation, security scanning, and regression testing.
-
Advise users not to install or execute analysis dependencies as root or through an unnecessarily privileged account.
-
