T08 · Insecure Dependencies
- Location
scripts/zotero_tool.py:246- Finding
Automatic Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/zotero_tool.py:246-256
Related Locations:scripts/requirements.txt:1;SKILL.md:41,58-70
Vulnerability Type: Supply-chain exposure through automatic, unpinned dependency installation
Risk Level: MediumComplete Code Snippet
python req_mod = requests if req_mod is None: print("dep_requests=missing") if args.auto_install_deps: print("dep_requests=installing") r = subprocess.run( [ sys.executable, "-m", "pip", "install", "requests>=2.31.0", ], capture_output=True, text=True, ) if r.returncode != 0: print("dep_requests=install_failed") print((r.stderr or r.stdout or "").strip()[:500]) return 10 import importlib req_mod = importlib.import_module("requests") print( f"dep_requests=installed version=" f"{getattr(req_mod, '__version__', 'unknown')}" )The dependency specification is also unpinned:
text requests>=2.31.0The documented workflow directs the Agent to invoke this behavior:
text Fixed workflow: run `doctor --auto-install-deps` first, and perform the import only after it passes.Technical Analysis
The
doctor --auto-install-depscommand invokes pip wheneverrequestsis unavailable. The version constraint permits any release at or above version 2.31.0 and does not provide an integrity hash, lock file, isolated environment, or enforced trusted package index.Python package installation may execute package build or installation logic. Consequently, the command establishes a code-execution path from the configured package source to the local environment. The affected package name is legitimate and no malicious dependency was observed in the audited project; the risk arises from mutable resolution an ...[truncated 2398 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from the runtime workflow. If
requestsis missing, stop and request explicit user-managed installation. - Pin dependencies to an audited exact version instead of using a lower-bound-only constraint.
- Generate and verify cryptographic hashes, for example with a hash-locked requirements file and
pip install --require-hashes. - Install dependencies in a dedicated virtual environment rather than modifying the Agent's active or global Python environment.
- Enforce a trusted package index and disable unintended extra indexes where operationally feasible.
- Separate environment provisioning from Skill execution so importing a PDF never implicitly performs package-management operations.
- If automatic installation must remain, require explicit user confirmation immediately before installation and display the exact package, version, index, and target environment.
- Maintain a reviewed lock file and periodically update it through a controlled dependency-review process.
- Remove automatic package installation from the runtime workflow. If
