T08 · Insecure Dependencies
- Location
SKILL.md:625- Finding
Unpinned Third-Party Dependencies Installed from Unverified Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 625–648
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
bash # Basic pip install requests beautifulsoup4 lxml pandas openpyxl # Dynamic pip install playwright playwright install chromium # Anti-detection pip install DrissionPage undetected-chromedriver fake-useragent # Framework pip install scrapy scrapy-redis # Async pip install aiohttp httpx # JS execution pip install PyExecJS # Node.js required for PyExecJS # Image processing pip install Pillow # OCR pip install ddddocr # Chinese captcha OCRTechnical Analysis
The Skill directs users to install numerous packages from the default Python package index without pinned versions, cryptographic hashes, a lockfile, or package-source restrictions. It also installs a browser binary through Playwright without specifying or validating the expected artifact version.
Python package installation can execute package-controlled build and installation hooks. If a referenced package or transitive dependency is compromised, taken over, replaced, or unexpectedly changed in a future release, installation may execute attacker-controlled code with the privileges of the user running
pip.The risk is increased by the breadth of optional dependencies. Packages providing browser automation, JavaScript execution, CAPTCHA processing, distributed crawling, and anti-detection features are recommended collectively even though many are unnecessary for a typical crawler. This exceeds minimum dependency privileges because users may install high-capability components unrelated to their specific task.
No evidence establishes that any named package is currently malicious. The vulnerability is the unsafe and non-reproducible dependency installation practice.
Attack Path
- An attacker compromises a named package, one of its ...[truncated 1575 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace free-form installation commands with a reviewed dependency manifest containing exact versions, such as
requirements.txtorpyproject.toml. -
Generate a hash-locked requirements file and require hash verification, for example:
bash python -m pip install --require-hashes -r requirements.lock -
Separate dependencies into minimal optional groups, such as
basic,browser,distributed, andocr, and instruct users to install only the group needed for the requested crawler. -
Pin and review all transitive dependencies using a reproducible locking tool such as
pip-tools, Poetry, or uv. -
Restrict installation to an approved package index or internal mirror and verify package ownership, provenance, release history, and signatures where available.
-
Install packages in an isolated virtual environment or disposable container using a non-root account and minimal filesystem and network permissions.
-
Add automated dependency scanning and update review rather than automatically accepting new releases.
-
Pin the Playwright package and browser revision together, and download browser artifacts only from an approved source with integrity validation.
-
Avoid including high-capability anti-detection, JavaScript-execution, distributed-crawling, or OCR packages unless the user’s requested functionality specifically requires them.
-
