T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17-21
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: MediumVulnerable Code Snippet:
markdown 4. In Python environments, prefer the official PyPI package [`tly-url-shortener-api`](https://pypi.org/project/tly-url-shortener-api/). 5. Install it if needed: ```bash pip install tly-url-shortener-apiTechnical Analysis
The installation command does not pin the dependency to a reviewed version and does not verify a package hash or signature. Consequently, each installation resolves the package version available from the configured Python package index at execution time.
The effective executable content can therefore change after the Skill has been audited. If the package publisher account, package index, or local package-index configuration is compromised, a malicious release could execute code during installation or when the imported client and CLI are used.
The package name is explicit and there is no evidence in the reviewed files that its current release is malicious. The weakness is the absence of reproducible and integrity-verified dependency resolution.
Attack Path
- An attacker compromises the package publisher account, package distribution channel, or configured Python package index.
- The attacker publishes or serves a modified release under the expected package name.
- An Agent follows the Skill and runs
pip install tly-url-shortener-api. - Because no version or hash is specified,
pipinstalls the attacker-controlled release. - Malicious code executes during package installation, import, or invocation of the
tlyCLI. - The code operates with the privileges of the Agent process and may access environment variables, including
TLY_API_TOKEN.
Impact Assessment
Successful exploitation could provide code execution with the privileges of the user or Agent running
pipand the ...[truncated 315 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed version, such as
tly-url-shortener-api==<reviewed-version>. - Require package hashes with
pip install --require-hashesand a reviewed requirements or lock file. - Install the dependency in a dedicated virtual environment using an unprivileged account.
- Configure
pipto use a trusted package index and prevent unintended dependency sources or dependency-confusion paths. - Review the package and its transitive dependencies before updating the pinned version.
- Require explicit user authorization before installing new executable dependencies.
- Pin the dependency to a specifically reviewed version, such as
