T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Mutable and Unverified Third-Party Dependency Installation
- Content
View full analysis
=0.11,<0.12 ``` ### Technical Analysis The Skill instructs the agent or user to install packages from the active Python package index before PDF extraction. The declared dependency uses a version range rather than an exact audited version, and the project does not provide package hashes or a lock file covering transitive dependencies. Consequently, installations performed at different times can resolve to different package artifacts. Pip will also use the environment's configured package indexes unless explicitly restricted. If an allowed release, one of its transitive dependencies, or a configured package index is compromised, attacker-controlled code could be installed. The installed dependency is subsequently imported by `scripts/fetch_report.py` during PDF extraction: ```python try: import pdfplumber except ImportError as exc: raise PipelineError( "tool_environment_error", "pdfplumber is required for PDF extraction", ) from exc ``` Importing a malicious Python package can execute attacker-controlled initialization code. This behavior exceeds the minimum supply-chain trust necessary because reproducible, hash-verified artifacts could be used instead. ### Attack Path 1. An attacker compromises a future package release accepted by `pdfplumber>=0.11,<0.12`, compromises a transitive dependency, or controls an active package index configured in the execution environment. 2. A user requests PDF extraction. 3. The agent or user follows the installation ...[truncated 1265 chars]- Remediation
View remediation
