T08 · Insecure Dependencies
- Location
capability/excel-result-export/formatted-export/SKILL.md:4- Finding
Unpinned Automatically Provisioned Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
capability/excel-result-export/formatted-export/SKILL.md:4
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code
yaml metadata: "{\"nanobot\": {\"requires\": {\"pip\": [\"pandas\", \"pyarrow\", \"openpyxl\"]}}}"Technical Analysis
The Skill declares automatically provisioned Python packages without exact version constraints or integrity hashes. Consequently, dependency resolution may install releases that differ from those present when the Skill was reviewed.
Package installation and import can execute package-controlled Python code. If a listed package, its distribution channel, or the configured package index is compromised, the Agent may install and execute malicious code under the runtime account. No evidence indicates that the named packages are currently malicious; the risk arises from unconstrained future dependency resolution and the absence of integrity verification.
Attack Path
- An attacker compromises a listed package release, its distribution account, or an untrusted package index used by the runtime.
- The attacker publishes a malicious release that still satisfies the unconstrained dependency declaration.
- The Skill environment resolves and installs that release.
- Malicious installation hooks or imported package initialization code executes with the Agent runtime's permissions.
- The malicious package can access data and resources available to that runtime, including spreadsheets being processed and writable output directories.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the privileges of the Agent runtime. The accessible scope may include input spreadsheet contents, generated reports, environment variables available to the process, and files writable by the runtime account. This declaration does not itself grant elevated system privileges, so imp ...[truncated 58 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency to a reviewed exact version, such as
package==version. - Maintain a lockfile generated from an approved dependency set.
- Require cryptographic hashes for downloaded distributions.
- Install packages exclusively from a trusted, explicitly configured package index.
- Prefer prebuilt, immutable runtime images containing audited dependencies rather than installing packages when the Skill runs.
- Continuously scan locked dependencies for known vulnerabilities and review changes before updating versions.
- Run dependency installation and Skill execution inside a least-privilege sandbox without unnecessary secrets or filesystem access.
- Pin every dependency to a reviewed exact version, such as
