T08 · Insecure Dependencies
- Location
SKILL.md:137- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 137
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: MediumRelevant snippet:
bash pip install md-exporterTechnical Analysis
The skill instructs users or agents to install
md-exporterdirectly from the package index without specifying an exact version, integrity hash, lock file, or verified source repository. Consequently, the dependency resolved during installation can differ from the version reviewed when the skill was published.If the package account, distribution channel, or a future release is compromised, package-controlled code may execute during source-package builds or when the installed conversion commands are invoked. The skill metadata claims version
3.6.11, but the installation command does not constrain the dependency to that version.No evidence establishes that the current package is malicious. The vulnerability is the absence of supply-chain controls around executable third-party code.
Attack Path
- An agent or user activates the skill and follows its installation instructions.
pipresolves the latest availablemd-exporterdistribution rather than a reviewed version.- An attacker compromises the package, publisher account, release process, or another component involved in dependency resolution.
- The victim installs the attacker-controlled release.
- Malicious code executes during a source build or when a documented
markdown-exportercommand is invoked. - The code operates with the privileges and file or network access of the account running the installation or conversion.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to Markdown inputs, generated documents, environment variables, API credentials available to the process, writable files, and reachab ...[truncated 141 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an explicitly reviewed version, such as
md-exporter==3.6.11, after verifying that this is the intended release. - Use hash-verified installation with a constraints or requirements file containing approved SHA-256 hashes.
- Publish the canonical source repository and package-index URL so users can verify package ownership.
- Maintain a lock file or signed software bill of materials covering all transitive dependencies.
- Install and execute the converter in an isolated virtual environment, container, or sandbox under a non-privileged account.
- Disable unnecessary network access during conversion and expose only required input and output directories.
- Re-audit dependency updates before changing the pinned version.
- Pin the dependency to an explicitly reviewed version, such as
