T08 · Insecure Dependencies
- Location
SKILL.md:94- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
=3.8", "numpy": ">=1.21.0" } ``` ### Technical Analysis The installation instructions tell users to install `numpy` without selecting an exact audited version or verifying an integrity hash. The metadata similarly defines only a lower version bound. Consequently, the package artifact installed in the future may differ from the artifact reviewed when this skill was published. Package installation is a code-execution boundary because Python packages may execute build backends or installation-related code. The actual source also depends on the user's configured package index and mirror settings. A compromised package publisher, package index, mirror, or local pip configuration could therefore cause a malicious artifact to be installed. The project uses the correct package name, so there is no evidence of deliberate typosquatting or dependency confusion in the audited files. The risk arises from mutable, unverified dependency resolution rather than a confirmed malicious dependency. ### Attack Path 1. A user follows the documented `pip install numpy` instruction. 2. Pip queries the configured package index or mirror and resolves a mutable package version. 3. An attacker has compromised the relevant publisher account, index, mirror, or package-resolution configuration. 4. Pip downloads a malicious or tampered distribution because no exact version and cryptographic hash are enforced. 5. Installation-related code executes with the privileges of the user running pip. 6. The installed dependency can subsequently execute again when `scripts/anoma ...[truncated 604 chars]- Remediation
View remediation
