T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Runtime Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–44
Vulnerability Type: Unpinned third-party dependencies and insufficient package-source isolation
Risk Level: MediumVulnerable Code
bash uv venv .venv --python 3.12 uv pip install --python .venv/bin/python click openai-whisper torch --index-url https://download.pytorch.org/whl/cpuTechnical Analysis
The documented installation command installs
click,openai-whisper, andtorchwithout fixed versions, a reviewed lockfile, or artifact integrity hashes. Consequently, separate installations can retrieve different direct or transitive dependency versions from those assessed during this audit.The command also applies
--index-url https://download.pytorch.org/whl/cputo the complete package transaction. This replaces the primary package index for every requested dependency rather than isolating the PyTorch repository to the package that requires it. Although the specified domain is the official PyTorch package source, using a single specialized index for unrelated packages weakens source separation and makes dependency resolution less explicit.Python packages can execute code during installation and whenever they are imported. The installed
clickandopenai-whisperpackages are imported byscripts/transcribe.py, while Whisper loads PyTorch as a runtime dependency. An upstream compromise, malicious dependency release, or unexpected mutable release could therefore introduce code not present in the audited project.No evidence was found that the project intentionally references a malicious package or attacker-controlled index. The risk arises from the non-reproducible and insufficiently constrained dependency installation process.
Attack Path
- An upstream package account, distribution artifact, or transitive dependency is compromised, or an unsafe future release becomes available.
- A user follows the installation instruc ...[truncated 1142 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an explicitly reviewed version.
- Generate and commit a dependency lockfile that constrains all transitive dependencies.
- Record and enforce cryptographic hashes for downloaded distributions where supported.
- Install
torchseparately from the official PyTorch CPU index so that the specialized index is scoped only to PyTorch:bash uv pip install --python .venv/bin/python \ --index-url https://download.pytorch.org/whl/cpu \ --require-hashes -r requirements-torch.lock - Install
click,openai-whisper, and their locked dependencies from official PyPI in a separate, hash-verified transaction:bash uv pip install --python .venv/bin/python \ --require-hashes -r requirements.lock - Review and update locked dependencies through a controlled process that includes vulnerability scanning, provenance verification, and functional testing.
- Avoid adding fallback or extra indexes unless strictly necessary; if one is required, document package-to-source mappings and ensure an unintended index cannot supply higher-priority package candidates.
