T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Python Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 215
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
python # Requires: pip install pytesseract pdf2imageTechnical Analysis
The OCR workflow directs users or agents to install
pytesseractandpdf2imagedirectly from the package index without specifying reviewed versions, cryptographic hashes, a lockfile, or an authenticated dependency manifest.Because package resolution depends on mutable registry state, future installations may retrieve releases or transitive dependencies that differ from those originally reviewed. If a package publisher account, package release, or dependency is compromised, malicious code could execute during installation or when the dependency is imported and used.
The audit found no evidence that either named package is currently malicious. The finding concerns the unsafe, non-reproducible installation mechanism.
Attack Path
- A user or agent follows the OCR instructions in
SKILL.md. - It runs
pip install pytesseract pdf2image. pipresolves the latest available package versions and their transitive dependencies.- If any resolved artifact has been compromised, its installation behavior or imported code executes locally.
- The malicious component operates with the permissions and data access of the Python environment running the Skill.
This path requires compromise of a named package, its publisher account, a transitive dependency, or the configured package-index infrastructure.
Impact Assessment
Successful supply-chain exploitation could provide arbitrary code execution with the privileges of the user running
pipor the PDF workflow. Accessible scope could include local PDF contents, generated outputs, files readable by that user, environment variables, and network resources available to the process.No privilege-escalation mechanism, persistence mechanism, credential harvestin ...[truncated 71 chars]
- A user or agent follows the OCR instructions in
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed, exact version.
- Commit a dependency lockfile that also fixes transitive dependency versions.
- Require cryptographic hashes for all downloaded artifacts, such as through a hashed requirements file and
pip install --require-hashes. - Configure installation to use an explicitly approved package index.
- Install dependencies inside a dedicated, least-privileged virtual environment or sandbox.
- Regularly scan and update pinned dependencies after security review.
- Document required non-Python components, including Tesseract OCR and Poppler, with trusted installation sources and reviewed versions.
A hardened example would use a reviewed requirements file:
bash python -m pip install --require-hashes -r requirements.txt
