T08 · Insecure Dependencies
- Location
SKILL.md:40- Finding
Unpinned dependencies installed outside an isolated environment
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:40
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: MediumVulnerable Code
bash pip install pymupdf openpyxl requests Pillow python-dotenv --break-system-packages -qTechnical Analysis
The installation command retrieves dependencies without pinning reviewed versions or verifying package hashes. Consequently, the code installed during each invocation may differ from the versions originally reviewed.
The
--break-system-packagesoption bypasses protections intended to preventpipfrom modifying a system-managed Python environment. This exceeds the minimum privileges necessary for the Skill because its dependencies can instead be installed in a dedicated virtual environment. The-qoption also suppresses installation details that could help users identify unexpected package sources or dependency changes.No dependency-confusion package name or known malicious dependency was identified in the reviewed project. The risk arises from unsafe supply-chain and environment-management practices rather than evidence that the listed packages are currently malicious.
Attack Path
- An attacker compromises a listed package, one of its transitive dependencies, or the package distribution channel.
- A user follows the installation command in
SKILL.md. - Because versions and hashes are not constrained,
pipresolves and downloads the attacker-controlled release. - Package installation or subsequent import executes the malicious component with the permissions of the user running the command.
- Because installation is allowed to modify the system-managed Python environment, the compromised component may affect other Python applications using that environment.
Impact Assessment
Successful exploitation could execute code with the invoking user's privileges, access files and credentials available to that user, alter ...[truncated 298 chars]
- Remediation
View remediation
Remediation Suggestions
- Create and use a dedicated virtual environment rather than passing
--break-system-packages. - Pin direct and transitive dependencies to reviewed versions in a lock file.
- Generate and enforce cryptographic hashes, for example with a hash-locked requirements file and
pip install --require-hashes. - Configure an explicit trusted package index and review transitive dependencies.
- Remove
-qso package resolution, source, and installation failures remain visible. - Run dependency installation and invoice processing as a non-privileged user.
- Add automated dependency vulnerability and provenance scanning to the release process.
A hardened workflow should resemble:
bash python -m venv .venv . .venv/bin/activate python -m pip install --require-hashes -r requirements.lock- Create and use a dedicated virtual environment rather than passing
