T08 · Insecure Dependencies
- Location
SKILL.md:34- Finding
Automatic Execution of Unreviewed Dependency Updates
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 34–39
Vulnerability Type: Supply-chain risk through automatic dependency updates
Risk Level: HighVulnerable Code
markdown ### Step 0: Keep the CLI up to date Every `snaplii` command prints an update notice to **stderr** when a newer release is available, e.g.: `[snaplii] Update available: 0.8.0 -> 0.9.0. Run 'snaplii update' or 'pip install -U snaplii-cli'.` If you see this notice, run `snaplii update` once, then continue. The check is cached (once per day) and never blocks normal commands.The initial installation instruction at line 26 also establishes reliance on the third-party package:
markdown 3. **Install the CLI** — `pip install snaplii-cli==0.13.2` ([PyPI](https://pypi.org/project/snaplii-cli/) | [Source](https://github.com/Snaplii-Inc/agent-to-merchant-payments))Technical Analysis
The initial installation pins
snaplii-clito version0.13.2, which provides some reproducibility. However, the Skill subsequently instructs the Agent to runsnaplii updateautomatically whenever the installed CLI prints an update notice to standard error.This instruction permits the currently installed dependency to decide when replacement executable code should be downloaded and installed. The update occurs without explicit user approval, a pinned target version, cryptographic hash verification, package-signature validation, or review of the new release. It therefore defeats the security benefit of the original version pin and allows the effective code executed by the Skill to change after audit.
The risk is especially significant because this CLI is instructed to process Snaplii API credentials, query financial balances, retrieve gift-card redemption information, and execute gift-card purchases and bill payments. Newly installed code would run with the local Agent process's operating-system privileges and could access information ...[truncated 2106 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to execute
snaplii updateautomatically. - Keep the CLI pinned to a specifically reviewed version and treat update notices as informational only.
- Require explicit user approval before installing or upgrading executable dependencies.
- Pin both the package version and an approved cryptographic hash, such as through a locked requirements file using
--require-hashes. - Verify package provenance and signatures where the distribution platform supports them.
- Review release notes and source changes before approving a new version, particularly changes involving authentication, credential storage, network destinations, gift-card details, or payment commands.
- Perform upgrades in an isolated environment with minimal filesystem and network privileges before deploying them to the environment containing real payment credentials.
- Ensure the CLI runs as an unprivileged user and cannot access unrelated secrets or files.
- Preserve the existing requirements for hidden API-key input, masked configuration output, explicit current-turn transaction confirmation, and no automatic payment retries.
- Remove the instruction to execute
