T08 · Insecure Dependencies
- Location
SKILL.md:327- Finding
Unpinned Third-Party Python Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:7,SKILL.md:327, andscripts/upload.py:9-10,29-33
Vulnerability Type: Unpinned dependency installation and supply-chain exposure
Risk Level: MediumComplete Code Snippets
From
SKILL.md:7:yaml dependencies: ["cryptography"]From
SKILL.md:327:text Requires: `pip install cryptography`From
scripts/upload.py:9-10:python Requirements: pip install cryptographyFrom
scripts/upload.py:29-33:python try: from cryptography.hazmat.primitives.ciphers.aead import AESGCM except ImportError: print("Error: 'cryptography' package is required for upload.") print("Install it with: pip install cryptography") sys.exit(1)Technical Analysis
The skill requires the
cryptographypackage but does not constrain it to a reviewed version or verify the integrity of the downloaded distribution. It also provides no lockfile or hash-locked requirements file. Runningpip install cryptographytherefore resolves a package dynamically from the Python package index configured in the user's environment.This creates supply-chain exposure if the configured package source, dependency resolution path, package release, or network environment is compromised. A malicious source distribution could execute code during package installation, while a malicious wheel or compromised package version could execute attacker-controlled code when imported by
scripts/upload.py.The package name itself is legitimate and no malicious dependency is present in the audited project. The risk arises from the uncontrolled version and artifact selection process.
Attack Path
- A user follows the skill documentation and runs
pip install cryptography. - Pip queries the package source configured in the user's environment.
- An attacker compromises that source, a resolved release, or the user's package-index configuration and serves a malicious artifact under the expecte ...[truncated 896 chars]
- A user follows the skill documentation and runs
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed version rather than resolving the latest available release:
text cryptography==REVIEWED_VERSION- Provide a hash-locked requirements file containing hashes for every supported distribution, then require hash verification:
bash python -m pip install --require-hashes -r requirements.txt-
Generate and review the lockfile through a controlled dependency-update process. Test and security-review new versions before updating the pin.
-
Use the official Python package index through authenticated TLS, and document that untrusted mirrors or additional package indexes must not be used.
-
Install the dependency inside a dedicated virtual environment with minimal privileges rather than into a system-wide or privileged Python environment.
-
Consider publishing a verified package or environment manifest for each supported platform so users can reproduce the reviewed dependency set.
