T08 · Insecure Dependencies
- Location
scripts/install.sh:17- Finding
Unpinned Third-Party Package Installed into the System Python Environment
- Content
View full analysis
/dev/null; then echo "📦 安装 python3-pip..." apt update && apt install -y python3-full python3-pip fi echo "✅ pip 已就绪" # 安装 aipyapp echo "📦 安装 aipyapp..." python3 -m pip install aipyapp --break-system-packages ``` `SKILL.md:26-33`: ```bash # 检查并安装 python3-pip apt update && apt install -y python3-full python3-pip # 安装 aipyapp python3 -m pip install aipyapp --break-system-packages ``` ### Technical Analysis The installation process retrieves `aipyapp` from the package index without specifying an audited version or cryptographic hash. Consequently, the package content installed at any given time can differ from the content that was previously reviewed. Python packages can execute arbitrary code during installation and when their modules or command-line entry points are used. If the upstream package, maintainer account, distribution infrastructure, or a future release is compromised, executing this installer can introduce attacker-controlled code. The `--break-system-packages` option bypasses Python's externally managed environment protection. Instead of isolating the dependency in a virtual environment, the command permits changes to the system Python environment. This can overwrite or conflict with packages used by other applications and broadens the effect of a compromised dependency. The repository does not include a lockfile, version constraint, hash manifest, vendored source, or other integrity control for the installed package. The external package's implementation therefore falls outside the reviewed project and cannot be verified by this static audit. ### Attack Path 1. An attacker compr ...[truncated 1551 chars]- Remediation
View remediation
