T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Package Retrieval and Execution Through uvx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–26
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash # Convert to stdout uvx markitdown input.pdf # Save to file uvx markitdown input.pdf -o output.md uvx markitdown input.docx > output.md # From stdin cat input.pdf | uvx markitdownThe Skill also documents an option that expands the executable dependency surface:
bash --use-plugins # Enable 3rd-party pluginsTechnical Analysis
The documented commands use
uvx markitdownwithout specifying an audited package version or verifying package integrity.uvxcan retrieve the package and its transitive dependencies from a configured package index before executing them. Consequently, the code that runs may change after this Skill has been reviewed.This creates a supply-chain risk if the package, one of its dependencies, the package index, or the package-resolution configuration is compromised. The optional
--use-pluginsflag further increases the risk because third-party plugin code may be loaded and executed without an allowlist or version constraints.Attack Path
- An attacker compromises a future
markitdownrelease, a transitive dependency, an enabled plugin, or the configured package source. - The user or Agent follows the Skill instructions and invokes
uvx markitdownwithout a pinned version. uvxresolves and downloads the attacker-controlled package or dependency.- The downloaded code executes with the same operating-system identity and permissions as the Agent.
- The malicious package can access documents supplied for conversion and any other resources available to that process.
Impact Assessment
Successful exploitation could result in arbitrary code execution with the invoking Agent's privileges. Depending on the Agent's environment, the malicious dependency could read ...[truncated 305 chars]
- An attacker compromises a future
- Remediation
View remediation
Remediation Suggestions
- Pin
markitdownto a specifically audited version in every command, rather than resolving the latest available release. - Use a lockfile or equivalent mechanism to pin and verify all transitive dependencies.
- Configure
uvxto use only an approved package index and apply available hash or signature verification. - Test dependency updates in a controlled environment before changing the pinned version.
- Run conversion in a sandbox with minimal filesystem access, restricted environment variables, and network access disabled unless necessary.
- Do not recommend
--use-pluginsby default. If plugin support is necessary, maintain an explicit allowlist and pin each plugin and its dependencies.
- Pin
