T08 · Insecure Dependencies
- Location
scripts/main.py:14- Finding
Unpinned Automatic Dependency Installation at Runtime
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/main.py:14-24scripts/submit_job.py:13-23scripts/query_job.py:14-24
Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: MediumVulnerable Code:
python def ensure_dependencies(): try: import tencentcloud # noqa: F401 except ImportError: print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr) ensure_dependencies()Equivalent dependency-installation logic is executed during module initialization in all three listed scripts.
Technical Analysis
When the
tencentcloudmodule is unavailable, each executable entry point invokespipto download and installtencentcloud-sdk-python. The dependency is not pinned to a reviewed version and no cryptographic hash is required. Pip also uses the runtime environment's configured package indexes and resolves transitive dependencies dynamically.This makes the effective code executed by the Skill mutable after the audited package has been published. A compromised upstream release, malicious package-index mirror, unsafe pip configuration, or compromised transitive dependency could introduce attacker-controlled code. Package installation and subsequent imports occur in the same process environment that later accesses Tencent Cloud credentials.
Although the automatic installation behavior is documented in
SKILL.md, that disclosure does not provide version integrity or protect the dependency supply chain.Attack Path
- A user or Agent invokes
main.py,submit_job.py, or `query_job. ...[truncated 1623 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove automatic package installation from all runtime entry points. If the dependency is absent, terminate with a clear setup error instead of invoking pip.
-
Declare dependencies in a committed lock file, package metadata, or deployment manifest.
-
Pin
tencentcloud-sdk-pythonand every transitive dependency to versions that have been reviewed and tested. -
Record and enforce cryptographic hashes, such as through:
bash python -m pip install --require-hashes -r requirements.txt -
Install dependencies during a controlled build or deployment phase rather than while processing a user request.
-
Use an isolated virtual environment or immutable container image containing preinstalled dependencies.
-
Restrict dependency retrieval to an approved package repository and verify package provenance where supported.
-
Run the Skill with least privilege and provide Tencent Cloud credentials restricted to only the required AI image-generation operations.
-
