T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:28-33
Vulnerability Type: Unpinned dependencies and unsafe supply-chain trust
Risk Level: MediumVulnerable Code
bash python3 -m pip install beautifulsoup4 lxmlThe same installation pattern also appears in
README.md:23-35, including:bash python3 -m pip install beautifulsoup4 lxml python3 -m pip install pytestTechnical Analysis
The skill directs users or agents to install packages without version constraints or cryptographic hash verification. Consequently, installation resolves whichever versions the configured Python package index serves at execution time. This prevents reproducible dependency resolution and implicitly trusts future upstream releases, mirrors, and local package-index configuration.
The risk is elevated for dependencies that may include native components, such as
lxml, because package installation and later import can execute package-controlled code with the privileges of the invoking process.No evidence indicates that the named packages are currently malicious. The vulnerability is the unsafe, mutable dependency-resolution process.
Attack Path
- A user invokes the skill in an environment where one or more dependencies are absent.
- The agent follows the documented instruction and runs the unpinned
pip installcommand. - An attacker has compromised a future upstream release, a configured package mirror, or the package-index resolution path.
pipdownloads and installs the attacker-controlled distribution.- Installation hooks or subsequent imports execute attacker-controlled code under the invoking user's account.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user running
pipor the conversion scripts. Accessible scope could include project files, EPUB inputs and outputs, environment variables, user-readable files, ...[truncated 146 chars]- Remediation
View remediation
Remediation Suggestions
- Define reviewed, exact dependency versions in a requirements or lock file.
- Record and verify distribution hashes using
pip install --require-hashes. - Install dependencies in a dedicated virtual environment with least privilege.
- Document and enforce the expected trusted package index rather than inheriting arbitrary index configuration.
- Use automated dependency review and vulnerability scanning before updating pinned versions.
- Separate runtime dependencies from development-only packages such as
pytest.
