T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Dependencies in OCR Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 215
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Mediumpython # Requires: pip install pytesseract pdf2imageTechnical Analysis
The OCR example instructs users or agents to install
pytesseractandpdf2imagewithout version constraints, package hashes, a lockfile, or an explicitly trusted package repository. Consequently, package resolution can select mutable releases that were not reviewed with the Skill.Python package installation may execute package-controlled build or installation logic. Installed packages also execute code when imported. If a dependency or one of its transitive dependencies is compromised, replaced with a malicious release, or resolved from an attacker-controlled package index, following this instruction could result in arbitrary code execution.
No evidence establishes that the named packages are currently malicious. The vulnerability arises from the unverified and non-reproducible dependency installation process.
Attack Path
- An attacker compromises a dependency release, a transitive dependency, or a package source accessible to the target environment.
- A user or agent follows the OCR prerequisite and runs
pip install pytesseract pdf2image. - Because no versions, hashes, or trusted repository are enforced,
pipresolves and downloads the attacker-controlled package artifact. - Malicious code executes during package build or installation, or later when the package is imported by the OCR example.
- The code operates with the privileges of the account running
pipor the subsequent Python process.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's privileges. Depending on that account's access, an attacker could read or modify local files, access PDF contents and process-visible secrets, alter generated output ...[truncated 215 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin each direct dependency to a reviewed, exact version.
-
Generate and retain a lockfile that also constrains transitive dependencies.
-
Require cryptographic hashes, such as with
pip install --require-hashes -r requirements.txt. -
Configure installation to use an explicitly trusted package index and disable unapproved extra indexes.
-
Install dependencies inside an isolated virtual environment or container under a least-privileged account.
-
Scan and periodically review dependency versions and transitive dependency changes.
-
Replace the inline installation instruction with a reviewed requirements file, for example:
text pytesseract==<reviewed-version> --hash=sha256:<verified-hash> pdf2image==<reviewed-version> --hash=sha256:<verified-hash> -
Document required system-level OCR components separately and verify their packages through the operating system's trusted package repository.
-
