T08 · Insecure Dependencies
- Location
references/setup-guide.md:4- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
references/setup-guide.md:4-5
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: MediumVulnerable Code
bash pip install requests beautifulsoup4 lxml python-Wappalyzer python-whois \ gspread google-auth aiohttp tldextract python-dotenvTechnical Analysis
The installation instructions fetch numerous third-party packages without exact version pins, package hashes, or a reviewed lockfile. Consequently, package resolution depends on mutable package-index state at installation time and can produce different dependency trees across installations.
Although the reviewed artifact contains no evidence that any named package is intentionally malicious, this installation pattern creates supply-chain exposure. A compromised package release, compromised transitive dependency, dependency-resolution change, or malicious replacement from an improperly configured package index could introduce attacker-controlled code.
Python packages and their build backends may execute code during installation. Installed dependencies also execute in the agent's runtime context, where they may access the process environment, local files available to the process, network resources, and data handled by the lead-generation workflow.
Attack Path
- An attacker compromises a listed package or one of its transitive dependencies, or causes dependency resolution to use an unsafe package source.
- The attacker publishes a malicious version that satisfies the unconstrained installation request.
- A user follows the setup guide and runs the documented
pip installcommand. - The malicious package executes code during package installation or when imported by the agent.
- That code accesses privileges available to the installing or runtime user. Depending on local configuration, this can include API keys stored in environment variables, the Google service-account JSON file, scrape ...[truncated 1024 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the unconstrained installation command with a reviewed dependency manifest that pins every direct and transitive dependency to an exact version.
- Generate and commit a lockfile using a suitable tool such as
pip-tools, Poetry, or Pipenv. - Require package hashes during installation, for example through a hash-locked requirements file and
pip install --require-hashes. - Install dependencies inside a dedicated virtual environment or isolated container rather than into a system-wide Python environment.
- Configure
pipto use only explicitly trusted package indexes and prevent unintended fallback to untrusted sources. - Scan dependencies with tools such as
pip-auditor OSV-Scanner in continuous integration and before releases. - Review dependency updates before regenerating the lockfile, rather than automatically accepting the newest available releases.
- Run the agent under a dedicated, non-privileged operating-system account and expose only the credentials required for the current operation.
- Restrict the Google service account to the intended sheet or minimum necessary resources, and rotate credentials if dependency compromise is suspected.
