T08 · Insecure Dependencies
- Location
references/setup.md:20- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
references/setup.md, line 20
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet:
markdown - Install the Python package `requests` before the first run, for example: `python -m pip install requests`Technical Analysis
The documented installation command resolves and installs whichever
requestsrelease is selected by the active Python package index at installation time. It provides neither a reviewed version constraint nor an integrity hash. The effective dependency can therefore change after the Skill has been audited.Although
requestsis a legitimate and correctly named package, this installation practice does not protect against a compromised upstream release, compromised package index, or attacker-controlled package mirror configured in the user's environment. Python package installation may execute build or installation logic, and the installed package subsequently executes code when imported byscripts/translate.py.Attack Path
- An attacker compromises a compatible package release, the configured package index, or a package mirror used by the victim.
- The user follows the documented command:
bash python -m pip install requests pipresolves and installs the compromised artifact because no reviewed version or hash is enforced.- Malicious code can execute during package installation or when
scripts/translate.pyimportsrequests. - The malicious dependency runs in the translation process and can access process data, files available to the user, media being processed, and the
KRETRANS_API_KEYenvironment variable.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user running
pipor the translation script. The scope may include theft of the KreTrans API credential, access to local media submitte ...[truncated 283 chars]- Remediation
View remediation
Remediation Suggestions
- Add a dependency manifest containing an explicitly reviewed
requestsversion. - Generate and verify cryptographic hashes for the package and all transitive dependencies.
- Require hash verification during installation, for example:
bash python -m pip install --require-hashes -r requirements.txt - Prefer binary wheels from a trusted, explicitly configured package index where practical.
- Review and update pinned dependencies through a controlled process that includes vulnerability scanning and testing.
- Recommend installation inside an isolated virtual environment under a non-privileged account.
- Avoid instructing users to run package installation with administrator or root privileges.
- Add a dependency manifest containing an explicitly reviewed
