T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Unpinned Third-Party SDK Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38–48
Vulnerability Type: Unpinned third-party dependency
Risk Level: Mediummarkdown ## Prerequisites 1. An iGPT API key (get one at https://igpt.ai/hub/apikeys/) 2. A connected email datasource -- the user must have completed OAuth authorization via `connectors/authorize` before ask will return results. You can check connection status with `datasources.list()`. 3. Python >= 3.8 with the `igptai` package installed ## Setup ```bash pip install igptaitext ### Technical Analysis The setup instructions install the latest available release of the third-party `igptai` package without specifying an exact version or verifying an integrity hash. The audited project contains no lockfile, hash-pinned requirements file, or vendored implementation that would make the installed dependency reproducible and reviewable. Consequently, the code executed by users may differ from the code that existed when this skill was reviewed. Installation hooks or imported package code can execute with the privileges of the user running `pip` or the skill. This finding concerns mutable dependency resolution; the audit found no evidence that the package is currently malicious. ### Attack Path 1. An attacker compromises the package publisher account, package repository, release process, or another relevant supply-chain component. 2. The attacker publishes a malicious or compromised release under the expected package name. 3. A user follows the documented `pip install igptai` command. 4. Package resolution retrieves the mutable latest release because no exact version or hash is required. 5. Malicious installation hooks or package code execute when the dependency is installed or imported. 6. The payload operates with the installing user's privileges and may attempt to access environment variables or data handled by the process. ### Impact Assessment Successful e ...[truncated 705 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the SDK to an exact, reviewed version rather than installing an unconstrained latest release:
text igptai==<reviewed-version> - Record cryptographic hashes in a requirements file and enforce them:
bash python -m pip install --require-hashes -r requirements.txt - Commit a reproducible lockfile or hash-pinned requirements file to the skill package.
- Install only from the expected package index over TLS and document the verified package publisher and source repository.
- Review dependency updates before changing the pinned version, including package provenance, release changes, transitive dependencies, and installation hooks.
- Run the SDK in a least-privileged, isolated environment with access only to the required API key and data.
- Avoid exposing unrelated credentials or sensitive environment variables to the process using the dependency.
- Pin the SDK to an exact, reviewed version rather than installing an unconstrained latest release:
