T08 · Insecure Dependencies
- Location
scripts/main.py:10- Finding
Unpinned Automatic Dependency Installation at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 10–18
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: MediumVulnerable Code:
python def ensure_dependencies(): try: import tencentcloud # noqa: F401 except ImportError: print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr) subprocess.check_call( [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"], stdout=sys.stderr, stderr=sys.stderr, )Technical Analysis
If the Tencent Cloud SDK cannot be imported, the script automatically invokes
pipto install the latest package resolved under the nametencentcloud-sdk-python. The installation uses no exact version pin, package hash verification, lockfile, trusted repository restriction, or explicit user approval.This makes the effective code executed by the Skill mutable after review. A compromised package release, malicious package-index mirror, or attacker-controlled Python package configuration could cause arbitrary installation or import-time code to run under the invoking user's identity. The dependency also executes in a process that can access the environment variables used for Tencent Cloud authentication.
Although the command uses a fixed argument list and does not introduce shell injection, unattended installation of an unverified dependency exceeds the minimum privileges needed for portrait segmentation. Dependency provisioning should occur through a controlled deployment process rather than during ordinary Skill execution.
Attack Path
- The Tencent Cloud SDK is absent from the runtime environment, causing the
ImportErrorbranch to execute. - An attacker compromises a future package release or influences package resolution through a malicious or compromised package index or mirror.
- The script invokes `py ...[truncated 1401 chars]
- The Tencent Cloud SDK is absent from the runtime environment, causing the
- Remediation
View remediation
Remediation Suggestions
- Remove automatic package installation from
main.py. If the SDK is unavailable, terminate safely with a concise dependency error. - Declare dependencies outside runtime code in a reviewed requirements or lock file.
- Pin the Tencent SDK to an exact, tested version rather than an open-ended package name.
- Record and verify package hashes, for example by installing from a hash-locked requirements file with:
bash python -m pip install --require-hashes -r requirements.txt - Restrict installation to an approved package index and a controlled build or deployment stage.
- Build and scan an immutable virtual environment or container before executing the Skill.
- Run the Skill as a minimally privileged account and use Tencent credentials restricted to only the API operations and resources required for portrait segmentation.
- Treat dependency installation failure as an operational error rather than silently modifying the environment.
- Remove automatic package installation from
