T08 · Insecure Dependencies
- Location
SKILL.md:21- Finding
Unpinned Third-Party Dependencies Permit Unreviewed Package Changes
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:21-25andSKILL.zh-CN.md:21-25
Vulnerability Type: Unpinned package installation
Risk Level: MediumThe installation instructions contain the following command:
bash pip3 install paddlepaddle paddleocrTechnical Analysis
The dependencies are installed without version constraints, integrity hashes, or a lock file. Consequently, each installation resolves whatever versions the configured Python package index currently considers appropriate.
Although the referenced package names appear consistent with the documented OCR functionality, the absence of version and integrity controls means that the installed code can change after the Skill has been reviewed. Python packages may execute code during installation and are imported by
scripts/ocr.py, so a compromised, malicious, or unexpectedly incompatible future release would execute with the permissions of the user running the installation or OCR script.The equivalent instruction is present in both the English and Chinese documentation.
Attack Path
- An attacker compromises a dependency release or the package-distribution account used to publish it.
- The attacker publishes a malicious version under one of the dependency names.
- A user follows the documented unpinned installation command.
pipresolves and installs the attacker-controlled release.- Malicious code executes during package installation or when
paddleocris imported by the OCR script.
This path depends on compromise of the selected package source or release process; the audited repository does not itself host an embedded malicious dependency.
Impact Assessment
Malicious dependency code would run with the privileges of the user executing
pipor the OCR script. It could access files, credentials, environment variables, and network resources available to that user, alter user-owned data, or execute additional pr ...[truncated 132 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version, for example through a version-controlled requirements file.
- Pin transitive dependencies with a lock-generation tool appropriate for Python.
- Require package hashes by installing with
pip install --require-hashes -r requirements.txt. - Use a trusted, explicitly configured package index and disable unexpected supplemental indexes.
- Add automated dependency vulnerability and provenance scanning.
- Review and update pinned versions through a controlled update process rather than resolving the latest versions during installation.
- Update both
SKILL.mdandSKILL.zh-CN.mdso that their installation instructions remain consistent.
