T08 · Insecure Dependencies
- Location
scripts/main.py:10- Finding
Unpinned Automatic Dependency Installation at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 10–19
Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: MediumVulnerable Code
python def ensure_dependencies(): try: import tencentcloud # noqa: F401 except ImportError: print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)Technical Analysis
The script automatically invokes
pipwhen the Tencent Cloud SDK cannot be imported. The package name is not pinned to a reviewed version, and no cryptographic hash or lock file is used to verify the installed artifact.Consequently, the effective code executed by the Skill can change after review as package indexes publish new releases or resolve different transitive dependencies. Python package installation may execute package-controlled build hooks, and imported package code subsequently executes in the Skill process.
Although the automatic installation behavior is disclosed in
SKILL.md, it exceeds the minimum privileges needed during normal Skill execution. Dependency resolution and installation should occur in a controlled deployment phase rather than while processing user images and cloud credentials.Attack Path
- The Skill runs in an environment where
tencentcloudis unavailable or its import is made to fail. ensure_dependencies()invokes the environment's Python interpreter with-m pip install tencentcloud-sdk-python -q.pipresolves the latest package and its transitive dependencies from its configured package source without version or hash verification.- A compromised upstream release, transitive dependency, configured pack ...[truncated 1103 chars]
- The Skill runs in an environment where
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from
scripts/main.py. If the dependency is absent, terminate with a clear setup error. - Install dependencies during a controlled build or deployment phase, before credentials or user images are made available.
- Pin the SDK and all transitive dependencies to reviewed versions in a lock file.
- Require cryptographic hashes during installation, such as:
bash python -m pip install --require-hashes -r requirements.txt - Use a trusted, explicitly configured package repository and prevent fallback to untrusted indexes.
- Build and scan an immutable virtual environment or container image, then run the Skill with package installation disabled.
- Run the Skill with a minimally privileged operating-system identity and narrowly scoped Tencent Cloud credentials.
- Regularly scan pinned dependencies for known vulnerabilities and update them through a reviewed release process.
- Remove automatic package installation from
