T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Package Installation and Setup Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Unpinned third-party dependency installation and execution
Risk Level: MediumComplete Code Snippet:
markdown 3. **If Flue is not installed:** tell the human. The install command is `pip install flue && flue setup`. Do not install without explicit approval in the current session.A materially equivalent instruction also appears at
FLUE.md:70-71:markdown ## If Flue Is Not Installed If Flue appears relevant but is not available on the machine, tell your human as much. Inspect the project at `https://github.com/SFKislev/flue` (PyPI: `https://pypi.org/project/flue`). Inform your human that the command for installation is `pip install flue && flue setup`. Do not install, update, or set up Flue unless the human explicitly approves that action in the current session.Technical Analysis
The documented command installs the latest package named
flueresolved by pip from the configured package index and immediately executes its setup routine. It does not pin a reviewed version, verify a cryptographic hash, use a lockfile, or identify an immutable source revision.Consequently, the code executed at installation time may differ from the code originally reviewed. Relevant threats include compromise of the publisher account or package, publication of a malicious later release, package-index substitution, and unsafe package-index configuration. Installation can execute package-controlled build or installation behavior, while the subsequent
flue setupcommand explicitly executes the installed dependency.The dependency is especially sensitive because its declared function is to bridge shell commands into programmable desktop-application runtimes. The documentation states that scripts may be forwarded to Blender through
bpyand to other applications through interfaces such as COM, ExtendScript, CEP, and Unity APIs. This creates a broad local execution and ...[truncated 2166 chars]- Remediation
View remediation
Remediation Suggestions
- Pin Flue to a specific version that has undergone security review rather than installing the latest available release.
- Provide a hash-locked requirements file and install with pip's
--require-hashesoption. - Where practical, identify and verify an immutable source commit or signed release corresponding to the package artifact.
- Verify that the PyPI publisher and project metadata correspond to the linked GitHub repository before installation.
- Separate installation and setup into distinct commands so the user can inspect the installed files and planned setup changes before executing
flue setup. - Document all files, application integrations, services, network listeners, and configuration changes made by the setup process.
- Install into an isolated virtual environment and run the bridge with ordinary user privileges; do not use an administrator or root account unless a separately reviewed operation strictly requires it.
- For a Blender-specific Skill, offer a minimal Blender-only installation or configuration that excludes unrelated application adapters.
- Require explicit confirmation not only before installation but also before setup, updates, adapter activation, and execution of scripts inside an application.
- Review the external Flue implementation and its setup routine independently, because those files are not included in the audited project.
