T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Unpinned Third-Party Dependencies and Unspecified External Package Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32-42
Vulnerability Type: Supply-chain exposure through unpinned dependencies and an unspecified third-party component source
Risk Level: MediumVulnerable Code Snippet
bash # Core dependencies (required) pip install httpx playwright openai-whisper moviepy # Playwright browser (required, run once) playwright install chromium # Optional dependencies # Bilibili video downloads require this # Xiaohongshu collection requires installing XHS-Downloader and providing a CookieTechnical Analysis
The setup instructions install
httpx,playwright,openai-whisper, andmoviepywithout exact version constraints, package hashes, or a reviewed lockfile. They also require a Chromium binary managed by Playwright. Consequently, the components installed at setup time can differ from those reviewed during the Skill audit.The optional
XHS-Downloadercomponent is referenced by name without an exact version, integrity checksum, or canonical repository URL. This creates additional ambiguity about which implementation the user should trust and install. Installation of Python packages can execute package-controlled build or installation logic, while downloaded browser binaries are executable components.This is a supply-chain weakness rather than evidence that the named dependencies are currently malicious.
Attack Path
- An attacker compromises a dependency release or distribution account, or publishes an impersonating component where users search for the unspecified
XHS-Downloader. - A user follows the Skill's setup instructions without a lockfile, hashes, or an authoritative source.
- The package manager or manual installation process retrieves the attacker-controlled release.
- Package installation, import, or later execution runs attacker-controlled code with the privileges of the user running the Skill.
- The malicious comp ...[truncated 771 chars]
- An attacker compromises a dependency release or distribution account, or publishes an impersonating component where users search for the unspecified
- Remediation
View remediation
Remediation Suggestions
- Pin every Python dependency to an audited exact version in a requirements or lock file.
- Require package hashes, such as with
pip install --require-hashes -r requirements.txt. - Document the canonical HTTPS repository and exact reviewed commit or signed release for
XHS-Downloader; do not instruct users to locate it by name alone. - Record and verify checksums or signatures for externally downloaded executable components, including browser binaries where supported.
- Run installation and execution in a dedicated virtual environment or isolated container under a non-privileged account.
- Regularly scan locked dependencies for known vulnerabilities and review changes before updating versions.
- Keep user cookies outside the project directory, restrict file permissions, and avoid exposing them to optional dependencies unless strictly necessary.
