T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned Dependencies Installed into the System Python Environment
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 22-26
Vulnerability Type: Unpinned and unsafe system-wide dependency installation
Risk Level: MediumVulnerable Code
markdown Before first use, install dependencies: ```bash pip install networkx matplotlib numpy --break-system-packagestext ### Technical Analysis The setup command installs three dependencies without version constraints, package hashes, or a reviewed lockfile. Consequently, the code installed by this skill can change over time even when the skill itself remains unchanged. The command also uses `--break-system-packages`, which deliberately bypasses Python environment protections intended to prevent `pip` from modifying an externally managed system Python installation. This can overwrite or conflict with packages used by unrelated applications. Package installation may execute package build hooks and installation logic. If the configured package index, a transitive dependency, or a future package release is compromised, following this instruction could execute attacker-controlled code. The risk is increased when the command is run with elevated privileges or inside an environment containing sensitive credentials. ### Attack Path 1. A user or agent follows the setup instructions in `SKILL.md`. 2. `pip` resolves the latest available versions of `networkx`, `matplotlib`, `numpy`, and their applicable dependencies from the configured package index. 3. An attacker compromises a package release, dependency, package-index configuration, or dependency resolution path. 4. `pip` downloads the attacker-controlled distribution. 5. Malicious build or installation logic executes with the privileges of the account running `pip`. 6. Because `--break-system-packages` permits changes to the externally managed Python environment, the installation can also alter packages used by unrelated system applications. ### Impact Assessment Successful exploitation can execute arbitrary ...[truncated 677 chars]- Remediation
View remediation
Remediation Suggestions
- Create and use an isolated virtual environment rather than modifying the system Python installation:
bash python3 -m venv .venv . .venv/bin/activate python -m pip install --upgrade pip python -m pip install -r requirements.txt-
Remove
--break-system-packagesfrom all installation instructions. -
Pin reviewed dependency versions in a requirements or lock file, including relevant transitive dependencies.
-
Generate and verify cryptographic hashes for distributions. For example, maintain a hash-locked requirements file and install it with:
bash python -m pip install --require-hashes -r requirements.txt-
Configure an explicitly trusted package index and avoid unreviewed mirrors or additional indexes that could enable dependency confusion.
-
Run dependency vulnerability and provenance checks as part of maintenance and CI, and update pinned versions through a controlled review process.
-
Document that dependency installation must run as an unprivileged user and must not be invoked through
sudo.
