T08 · Insecure Dependencies
- Location
prompt.md:184- Finding
Automatic Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
prompt.md:40-43,prompt.md:184-188
Related Documentation:SKILL.md:129-131,README.md:91-92,README.md:104-106
Vulnerability Type: Supply-chain exposure through unpinned and unattended package installation
Risk Level: MediumVulnerable Code
markdown 2. **Ensure yt-dlp Python module is available** - Check if yt-dlp is installed: `python3 -c "import yt_dlp" 2>/dev/null` - If not, auto-install: `pip install yt-dlp` - This is transparent to the userbash python3 -c "import yt_dlp" 2>/dev/null || pip install -q yt-dlpTechnical Analysis
The skill directs the Agent to install
yt-dlpautomatically when the module cannot be imported. The installation command does not pin a reviewed version, verify package hashes, use a lockfile, constrain the package index, or request explicit user approval.Consequently, the code installed and subsequently imported can change independently of the reviewed skill. The effective source also depends on the runtime pip configuration, including configured indexes and mirrors. A compromised upstream release, package index, mirror, dependency, or local pip configuration could therefore cause attacker-controlled code to execute in the Agent's environment.
The quiet installation option and instruction that installation should be transparent to the user further reduce visibility into this security-sensitive environmental modification.
Attack Path
- A user invokes the skill on a system where the
yt_dlpPython module is unavailable. - The Agent executes the prescribed import check.
- The import check fails and triggers
pip install -q yt-dlp. - Pip resolves the unpinned package and transitive dependencies through the environment's configured package index.
- A compromised package release, dependency, mirror, or index response supplies malicious code.
- The package or its depende ...[truncated 768 chars]
- A user invokes the skill on a system where the
- Remediation
View remediation
Remediation Suggestions
- Remove transparent dependency installation from normal skill execution.
- Require explicit user approval before modifying the Python environment.
- Pin
yt-dlpand every relevant dependency to reviewed versions. - Verify packages using hashes, such as with a hash-locked requirements file and
pip --require-hashes. - Use
python3 -m pipto ensure installation targets the intended interpreter. - Install dependencies inside a dedicated, least-privileged virtual environment rather than the Agent's global or user environment.
- Restrict resolution to an approved package index or internally controlled artifact repository.
- Display the package version and source before installation instead of using quiet, transparent installation.
- Prefer a deployment process that installs and verifies dependencies before the skill is invoked.
