T08 · Insecure Dependencies
- Location
scripts/runner.sh:7- Finding
Automatic Installation of an Unpinned Runtime Dependency
- Content
View full analysis
=1.21.0 ``` ### Technical Analysis The launcher automatically invokes `pip install numpy -q` during normal execution whenever the local virtual environment does not exist. This downloads and installs the latest compatible package selected by the active Python package index and local pip configuration. Neither the launcher nor `requirements.txt` specifies: - An exact reviewed package version - Package hashes - An explicitly trusted package index - A reproducible lock file - A separate, user-reviewed installation phase Python package installation can execute package build or installation logic with the privileges of the user running the Skill. The use of quiet mode also suppresses information that would otherwise help users inspect dependency resolution and installation failures. No evidence was found that the project intentionally references a malicious package. The risk arises from unsafe and non-reproducible dependency resolution. ### Attack Path 1. A user invokes `scripts/runner.sh`. 2. The expected `venv` directory is absent. 3. The script creates and activates a virtual environment. 4. The script contacts the package index configured for pip and resolves an uncontrolled compatible NumPy release. 5. If the selected package source or release is compromised, malicious installation logic executes with the invoking user's permissions. 6. The installed package can subsequently execute again when imported by `scripts/prediction_model.py`. Exploita ...[truncated 632 chars]- Remediation
View remediation
``` 2. Generate a hash-locked dependency file and require hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Move dependency installation into an explicit setup step rather than performing it automatically during every first run. 4. Invoke pip through the selected interpreter to prevent executable ambiguity: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 5. Configure an explicitly trusted package index or an organization-controlled artifact repository. 6. Remove quiet mode so that users and automated logs can inspect the selected source, version, and installation errors. 7. Add automated dependency review and vulnerability scanning for every lock-file update. ]]>
