T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party Package Installation from a Mutable Git Repository
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–27
Vulnerability Type: Unpinned dependency retrieved from an unsafe mutable source
Risk Level: Mediumbash # Install pip install git+https://github.com/lrg913427-dot/agent-lens.gitTechnical Analysis
The documented installation command retrieves and installs the current default branch of a third-party personal GitHub repository. It does not specify an immutable release tag or full commit SHA, and it provides no cryptographic hash, signature, or provenance verification.
Consequently, the code installed by users can differ from the code that was originally reviewed. Python package installation may execute repository-controlled build or installation logic. A malicious commit, compromised maintainer account, repository ownership transfer, or other supply-chain compromise could therefore introduce code that runs during installation.
The project contains only
SKILL.md; the referenced external repository and its package implementation were not included in the audit scope. No claim is made that the current external package is malicious. The confirmed issue is the unsafe, mutable installation mechanism.Attack Path
- An attacker compromises the repository maintainer account, gains control of the repository, or causes a malicious commit to enter its default branch.
- The attacker adds malicious Python packaging, build, or runtime code.
- A user follows the Skill documentation and runs the unpinned
pip install git+https://github.com/lrg913427-dot/agent-lens.gitcommand. pipdownloads the repository’s current attacker-controlled content rather than an immutable reviewed revision.- Malicious build or installation code executes with the privileges of the user running
pip; malicious runtime code may also execute when the package is imported or its CLI is invoked.
Impact Assessment
Successful exploitation could provide arbit ...[truncated 627 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer a reviewed package published through a trusted registry and pin an exact version rather than installing the repository’s mutable default branch.
- Use a lock file or requirements file with cryptographic hashes, such as pip hash-checking mode, to verify downloaded artifacts.
- If Git installation is unavoidable, pin the dependency to a reviewed full commit SHA instead of a branch or floating tag.
- Verify signed commits or release artifacts and document the expected repository owner, revision, and artifact digest.
- Review the dependency’s source code and packaging configuration before approving an updated revision.
- Perform installation in an isolated virtual environment or sandbox using a non-privileged account, and avoid exposing unnecessary credentials during installation.
- Establish an update process in which dependency revisions are explicitly reviewed, tested, and approved before changing the pinned version.
