T08 · Insecure Dependencies
- Location
SKILL.md:265- Finding
Unpinned third-party dependencies create a supply-chain risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:265
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Code
text pip install numpy pandas scikit-learn tensorflowTechnical Analysis
The installation command does not specify package versions, integrity hashes, or an explicitly trusted package index. Package resolution can therefore change between installations. Pip installation may also execute package build hooks or other installation logic under the privileges of the invoking user.
This does not establish that the named packages are malicious. However, it creates an avoidable supply-chain exposure if an upstream release, dependency, configured package index, or resolved artifact is compromised. It also prevents reproducible security review because future installations may retrieve code different from the code originally assessed.
Attack Path
- A user follows the documented environment setup command.
- Pip resolves the latest compatible packages and transitive dependencies from the configured index.
- An upstream package, transitive dependency, package-index account, mirror, or artifact is compromised.
- Pip downloads the compromised artifact because no approved version or hash is enforced.
- Malicious installation logic or imported package code executes with the privileges of the user running pip.
Impact Assessment
Successful exploitation could execute arbitrary code in the installation environment. The attacker could access files, environment variables, API credentials, network resources, and application data available to the invoking account. If installation is performed with elevated privileges, the impact could extend to system-wide files and configuration. The exact scope remains constrained by the operating-system account, container, sandbox, and network controls in effect.
- Remediation
View remediation
Remediation Suggestions
- Replace the ad hoc installation command with a reviewed lock file containing exact direct and transitive dependency versions.
- Require artifact hashes, such as by using
pip install --require-hashes -r requirements.txt. - Configure an explicit, trusted package index or an internally controlled artifact repository.
- Scan locked dependencies for known vulnerabilities and review updates before changing the lock file.
- Install dependencies inside an isolated virtual environment or container as an unprivileged user.
- Separate heavyweight optional dependencies from the minimum runtime requirements.
- Document the source and reviewed version of the referenced
multi_researchmodule before instructing users to import or install it.
