T08 · Insecure Dependencies
- Location
SKILL.md:50- Finding
Automatic Installation and Execution of an Unpinned Third-Party Dependency
- Content
View full analysis
/dev/null || pip install kb-lint kb-lint --format json --severity info 2>&1 ``` ``` ### Technical Analysis The Skill instructs the Agent to install `kb-lint` from a package registry whenever the command is unavailable. Neither the installation metadata nor the fallback command pins an exact package version, verifies an artifact hash, uses a lockfile, or validates the package publisher. The dependency's source code is not included in the audited project, so its installation hooks and runtime behavior cannot be verified from the available artifact. The effective code executed by the Skill can also change whenever a new package version is published. This creates a supply-chain risk: compromise of the legitimate package, its publisher account, the package registry, or dependency resolution could result in attacker-controlled code being installed and executed with the Agent's privileges. ### Attack Path 1. An attacker compromises the `kb-lint` distribution channel, publisher account, package release, or one of its unresolved dependencies. 2. The malicious or compromised release becomes the version selected by `pip` or `uv`. 3. A user invokes the Skill on a system where `kb-lint` is unavailable. 4. The command `pip install kb-lint` downloads and installs the unpinned release. 5. Package installation behavior or the subsequent `kb-lint` invocation executes attacker-controlled code. 6. That code operates with the Agent process's permissions and can access files and resources available to the Agent. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the user runn ...[truncated 505 chars]- Remediation
View remediation
