T08 · Insecure Dependencies
- Location
SKILL.md:96- Finding
External CLI Installation Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 96-110; equivalent installation guidance is repeated at lines 329-337
Vulnerability Type: Insecure third-party dependency installation
Risk Level: MediumVulnerable Code
bash ### Python CLI Install Prefer installing the latest published PyPI package: ```bash py -3 -m pip install okfile okfile --versionIf you need a pinned install for reproducibility:
bash py -3 -m pip install okfile==1.2.3Upgrade an existing install:
bash py -3 -m pip install --upgrade okfileIf you need a direct static artifact instead of PyPI, install the wheel from OkFile:
bash py -3 -m pip install "https://www.okfile.com/downloads/okfile-1.2.3-py3-none-any.whl"text ### Technical Analysis The Skill instructs users or agents to download, install, and execute an external Python package that is not included in the audited project. The default installation and upgrade commands do not pin a version, so the downloaded implementation can change after this Skill has been reviewed. Although one command pins version `1.2.3`, neither that command nor the vendor-hosted wheel installation verifies a cryptographic hash or signature. The repository contains only `SKILL.md`; therefore, the effective behavior of the installed `okfile` executable cannot be verified from the audited artifact. This creates a supply-chain trust boundary around the PyPI package, its maintainer account, package distribution infrastructure, the vendor website, and the downloaded artifact. This finding does not establish that the current package is malicious. The risk arises because the instructions allow unreviewed or subsequently modified third-party code to be installed and executed without integrity validation. ### Attack Path 1. An attacker compromises the package publisher account, package registry, vendor download infrastructure, or a future package release. ...[truncated 1291 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, reviewed version instead of recommending an unversioned installation or automatic upgrade.
- Publish and document a trusted SHA-256 digest for the approved wheel.
- Require hash verification, preferably through a locked requirements file and pip's
--require-hashesoption. - Avoid direct vendor-hosted artifact installation unless the artifact is authenticated through a verified signature or pinned cryptographic digest.
- Vendor the reviewed CLI source or wheel within a controlled release process when feasible, so its contents are covered by the Skill audit.
- Remove or discourage
pip install --upgrade okfilefrom automated workflows because it permits unreviewed future releases. - Install the dependency in an isolated virtual environment or restricted container and run it without administrative privileges.
- Treat package updates as security-sensitive changes and repeat source, dependency, and artifact review before updating the pinned version.
