T08 · Insecure Dependencies
- Location
scripts/main.py:14- Finding
Automatic Installation of an Unpinned Runtime Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 14–24
Vulnerability Type: Unpinned automatic dependency installation
Risk Level: MediumVulnerable Code
python def ensure_dependencies(): try: import tencentcloud # noqa: F401 except ImportError: print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, ) print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)Technical Analysis
When the Tencent Cloud SDK is unavailable, the Skill automatically invokes pip to download and install the latest package matching
tencentcloud-sdk-python. The command does not specify an audited version, verify package hashes, use a lockfile, or enforce an explicitly trusted package index.Consequently, the code executed by the Skill can change after the Skill itself has been reviewed. Package resolution also inherits the Python environment's pip configuration, including configured indexes and mirrors. A compromised upstream release, package repository, or configured mirror could therefore supply malicious installation or runtime code.
Runtime installation is unnecessary for the core image-to-video operation and modifies the Python environment without a separate controlled setup phase. The project documentation also recommends installing the unpinned packages
tencentcloud-sdk-pythonandrequests, althoughrequestsis not directly used by the audited script.Attack Path
- An attacker compromises a package release, configured pip index, package mirror, or another relevant dependency-resolution component.
- The Skill is executed in an environment where the
tencentcloudmodule is not installed. - `ensure_depende ...[truncated 1322 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from
scripts/main.py. If the dependency is missing, terminate with a clear error that identifies the controlled setup procedure. - Install dependencies during a separate build or deployment phase rather than while processing user input.
- Pin the Tencent Cloud SDK to a reviewed version in a dependency manifest or lockfile.
- Require cryptographic hashes for downloaded distributions, such as with pip's
--require-hashesoption and a hash-pinned requirements file. - Configure an explicitly trusted package index or an internally controlled artifact repository instead of inheriting arbitrary runtime pip configuration.
- Build and run the Skill in an isolated virtual environment or container with minimal filesystem and network privileges.
- Remove
requestsfrom the installation documentation unless it becomes a direct, necessary dependency. - Use a least-privileged Tencent Cloud identity restricted to the video-effects operations and resources required by this Skill.
- Remove automatic package installation from
