T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Installation and Setup
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16andFLUE.md:72
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: MediumRelevant Snippets:
SKILL.md:16:markdown 4. **If Flue is not installed:** tell the human. The install command is `pip install flue && flue setup`. Do not install without explicit approval in the current session.FLUE.md:72:markdown If Flue appears relevant but is not available on the machine, tell your human as much. Inspect the project at `https://github.com/SFKislev/flue` (PyPI: `https://pypi.org/project/flue`). Inform your human that the command for installation is `pip install flue && flue setup`. Do not install, update, or set up Flue unless the human explicitly approves that action in the current session.Technical Analysis
The documented installation command retrieves the current
fluerelease from the package index without specifying a reviewed version, enforcing package hashes, or validating the resolved artifact. It then immediately invokes the package-controlledflue setupcommand.User approval reduces the likelihood of an unexpected installation but does not address dependency integrity. If the upstream project, maintainer account, distribution infrastructure, or a newly published package release is compromised, the command can retrieve and run code that was not present during this audit. The audited project contains only documentation and does not include the Flue package implementation, a lockfile, artifact hashes, or other material that would permit verification of the installed code.
Attack Path
- An attacker compromises the upstream package, its publication credentials, or a future package release.
- The attacker publishes a modified package under the expected
fluepackage name. - A user approves installation after following the Skill documentation.
- `pip insta ...[truncated 970 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Flue to a specifically reviewed version instead of installing the latest release:
shell python -m pip install "flue==<reviewed-version>" - Download and inspect the resolved wheel before installation.
- Verify the package with an approved SHA-256 hash, such as through a requirements file using
--require-hashes. - Separate installation and setup into distinct commands so users can review the installed files and setup behavior before execution.
- Install into an isolated virtual environment and run with the minimum required user privileges.
- Document the expected package publisher, release version, artifact hash, and source revision.
- Avoid elevated shells unless a reviewed adapter explicitly requires elevation.
- Periodically reassess the pinned release and update only after reviewing its source and setup behavior.
- Pin Flue to a specifically reviewed version instead of installing the latest release:
