T08 · Insecure Dependencies
- Location
SKILL.md:100- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:100-106
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: MediumVulnerable Code
bash pip install "markitdown[all]" pipx install 'markitdown[all]'Technical Analysis
The installation instructions retrieve the latest available version of
markitdownand all optional dependencies without a version constraint, lockfile, or cryptographic integrity hashes. Installing theallextra also expands the supply-chain attack surface by resolving numerous optional transitive packages that may not be required for every use case.Although the documented package is consistent with the Skill's stated purpose, installation is not reproducible and the exact dependency set cannot be verified against the audited project. An upstream compromise, malicious transitive release, dependency confusion event, or unexpected incompatible update could therefore introduce attacker-controlled code after this Skill has been reviewed.
Attack Path
- An attacker compromises the upstream package, one of its optional transitive dependencies, or the relevant package-distribution account.
- The attacker publishes a malicious release that satisfies the unrestricted dependency specification.
- A user follows the documented
pip install "markitdown[all]"orpipx install 'markitdown[all]'instructions. - The package manager resolves and installs the malicious release because no audited version or integrity hash is required.
- Malicious code may execute during source-package build or later when the installed package is imported and used by the scripts.
Impact Assessment
Successful exploitation could execute code with the privileges of the account performing the installation or running the conversion scripts. This may permit access to that user's readable documents, environment variables, credentials, output files, and other accessible local resources.
The impact is gener ...[truncated 274 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
markitdownto a specifically reviewed version rather than installing an unrestricted latest release. - Generate and commit a dependency lockfile containing exact versions for all transitive dependencies.
- Require cryptographic package hashes, such as through a hashed requirements file and
pip install --require-hashes. - Install only the optional extras required by the intended conversion formats instead of using the broad
allextra. - Perform installation in an isolated virtual environment under an unprivileged account.
- Add automated dependency vulnerability and provenance scanning to the release process.
- Review and deliberately update dependency pins rather than allowing package resolution to change on each installation.
- Pin
