T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25-27
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
bash pip install neural-memory nmem initTechnical Analysis
The setup instructions install
neural-memoryfrom the active Python package index without specifying an exact version, package hash, verified repository, or trusted index. The installed package is then immediately executed throughnmem init.Because the dependency is unpinned, the code installed by the same reviewed Skill can change over time. A compromised publisher account, compromised package release, dependency-confusion condition, or malicious package served by a configured package index could result in arbitrary Python package installation or initialization code running locally.
The project contains only
SKILL.md, so the implementation and provenance of the referenced package could not be verified within the audited artifact.Attack Path
- An attacker compromises the package, its publishing account, a transitive dependency, or a package index used by the victim.
- The attacker publishes a malicious release under the dependency name or causes package resolution to select an attacker-controlled distribution.
- A user follows the Skill instructions and runs
pip install neural-memory. - Package installation behavior executes, after which the user runs the installed
nmem initcommand. - Malicious package code executes with the privileges of the user who performed the installation.
Impact Assessment
Successful exploitation can provide arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, malicious code could read or alter accessible files, environment variables, credentials, project data, and local application state. It could also establish additional persistence or communicate with external servic ...[truncated 76 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed version, such as
neural-memory==X.Y.Z. - Require hash verification with a locked requirements file and
pip install --require-hashes. - Document the official package repository, publisher identity, and trusted package index.
- Audit direct and transitive dependencies before approving upgrades.
- Install the package in a dedicated virtual environment or other least-privilege sandbox.
- Separate installation from execution and ask the user to verify the resolved package source and version before running
nmem init. - Consider distributing a reproducible, signed lock file or verified package artifact.
- Pin the dependency to a specifically reviewed version, such as
