T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 19
Vulnerability Type: Unverified runtime dependency installation
Risk Level: MediumEvidence:
text 1. Confirm that python-docx is installed: `pip install python-docx`The snippet above is an English rendering of the instruction at the specified source location.
Technical Analysis
The Skill instructs the agent to install
python-docxdirectly from the configured Python package index. It does not specify a reviewed version, require package hashes, use a lockfile, constrain the package source, or require an isolated environment.Because package installation can execute package build and installation logic, the effective code being trusted is not fully determined by the audited project. A compromised package release, compromised package index, malicious index configuration, or unexpected future dependency change could introduce code that was not present during this audit.
The package name is consistent with the expected legitimate library; no evidence of typosquatting or an intentionally malicious package was found. The risk arises from the unsafe, unpinned installation procedure.
Attack Path
- A user invokes the Skill on a system where
python-docxis unavailable. - Following
SKILL.md, the agent executespip install python-docx. pipresolves the package and its transitive dependencies from the environment's configured package index.- If the index, selected release, dependency chain, or local package-index configuration is compromised, malicious installation or package code is retrieved.
- That code executes with the privileges of the account running the agent or is later executed when imported.
Exploitation therefore depends on compromise or manipulation of the relevant Python supply chain or package-index configuration.
Impact Assessment
Successful exploitation could execute arbitrary code with the privi ...[truncated 501 chars]
- A user invokes the Skill on a system where
- Remediation
View remediation
Remediation Suggestions
- Pin
python-docxand all transitive dependencies to reviewed versions. - Maintain a lockfile or requirements file containing cryptographic hashes, and install with hash verification.
- Use an explicitly trusted package index rather than inheriting an unknown environment configuration.
- Install dependencies inside a dedicated virtual environment with the minimum required permissions.
- Do not install packages automatically. Inform the user of the required dependency and obtain explicit approval before changing the environment.
- Prefer a prebuilt, reviewed execution environment in which dependencies are already installed.
- Periodically scan pinned packages for known vulnerabilities and update them through a controlled review process.
- Pin
