T08 · Insecure Dependencies
- Location
replicate.md:10- Finding
Unpinned Replicate Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
replicate.md:10
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code:
bash pip install replicateTechnical Analysis
The setup command installs the latest package release resolved by the configured Python package index. It does not specify a reviewed version, verify package hashes, use a lockfile, or require an isolated environment.
As a result, the installed code can change after the Skill has been audited. A compromised upstream release, compromised package-index account, or unsafe package-index configuration could introduce malicious installation or runtime code.
Attack Path
- An attacker compromises the upstream package, maintainer account, release process, or package source used by pip.
- A malicious version becomes the version selected by the unpinned command.
- A user follows the documented setup instructions.
- Pip downloads and installs the mutable release.
- Malicious installation hooks or imported package code execute with the privileges of the user running pip.
Impact Assessment
Successful exploitation could execute arbitrary code under the installing user's account. This may expose files, environment variables, API tokens, and other resources accessible to that account. It does not directly provide administrator privileges unless installation is separately performed with elevated permissions.
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed version, such as
replicate==<reviewed-version>. - Publish a requirements or lock file containing exact transitive dependency versions.
- Record and verify package hashes with
pip install --require-hashes. - Recommend installation inside a dedicated virtual environment.
- Configure pip to use an explicitly trusted package index.
- Add a controlled dependency-update process that includes security review and testing.
- Pin the dependency to a reviewed version, such as
