T08 · Insecure Dependencies
- Location
SKILL.md:63- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63-79
Vulnerability Type: Unpinned and unverifiable Python dependencies
Risk Level: MediumVulnerable Code
markdown **本地直接运行**:进入本 skill 所在目录(或把 `scripts/` 加入路径),先 `pip install -r scripts/requirements.txt`,再执行 `python scripts/脚本名.py --help` 看参数,或按上表传参运行。bash pip install openpyxl pandas xlrdmarkdown 或使用 skill 自带:`pip install -r scripts/requirements.txt`Technical Analysis
The Skill instructs users or agents to install
openpyxl,pandas, andxlrdwithout exact versions or integrity hashes. Consequently, package resolution depends on mutable repository state at installation time rather than a reviewed and reproducible dependency set.The alternative installation command references
scripts/requirements.txt, but that file is absent from the audited artifact. Its contents therefore cannot be inspected, and the command cannot work with the package as supplied. The artifact contains onlySKILL.md.This is a supply-chain weakness rather than evidence that the named packages are malicious. Exploitation would require compromise of the configured package source, an unsafe future package release, or package-index configuration that resolves an unintended component.
Attack Path
- An agent loads the Skill and follows its documented setup procedure.
- The agent runs
pip install openpyxl pandas xlrdwithout version or hash constraints. pipqueries the environment's configured package indexes and resolves the packages available at that time.- If an upstream release or configured index has been compromised, attacker-controlled installation or runtime code is installed.
- Package installation hooks may execute during installation; package code may also execute when imported during subsequent Excel processing.
The
scripts/requirements.txtroute is not directly exploitable from the audited artifact because that file is missing, but its absence pr ...[truncated 658 chars]- Remediation
View remediation
Remediation Suggestions
- Add an auditable dependency lock file to the project and pin every direct and transitive dependency to an exact reviewed version.
- Record cryptographic hashes and enforce them during installation:
bash python -m pip install --require-hashes -r scripts/requirements.txt - Generate and review the lock file using a dependency-management tool such as
pip-tools, then commit the generated file with the Skill. - Install dependencies in an isolated virtual environment under a non-privileged account:
bash python -m venv .venv . .venv/bin/activate python -m pip install --require-hashes -r scripts/requirements.txt - Configure trusted package indexes explicitly and prevent fallback to unreviewed or user-controlled indexes.
- Scan locked dependencies for known vulnerabilities and review updates before changing pinned versions.
- Either include the referenced
scripts/directory andscripts/requirements.txtin the distributed artifact or remove all claims that these files are bundled.
