T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 7
Vulnerability Type: Unpinned dependencies installed from the active pip package index
Risk Level: MediumVulnerable Code
yaml dependencies: "pip install python-docx fpdf2"Technical Analysis
The skill directs users or the runtime to install
python-docxandfpdf2without pinned versions, package hashes, or an explicitly trusted package index. Dependency resolution therefore relies on mutable package releases and the current pip configuration. This makes installations non-reproducible and exposes them to compromised upstream releases, transitive-dependency compromise, or a malicious package index configured in the environment.The embedded Python example only imports and uses
python-docx;fpdf2is not used. Installing this unnecessary dependency expands the supply-chain attack surface without supporting the demonstrated functionality.This finding does not prove that either named package is malicious. The weakness is the unsafe and unconstrained installation process.
Attack Path
- A user or automation framework loads the skill and follows its dependency declaration.
- It executes
pip install python-docx fpdf2. - pip resolves the latest compatible packages and transitive dependencies through the environment's configured index.
- An attacker compromises a package release or dependency, or controls a configured package index and serves a malicious artifact.
- pip downloads and installs that artifact.
- Malicious installation or imported runtime code executes with the privileges of the account performing installation or running the skill.
Impact Assessment
Successful exploitation could execute arbitrary code under the installing or runtime user's privileges. Depending on those privileges, the attacker could access files and credentials available to that account, alter generated documents, tamper with the local environment, or establish further compr ...[truncated 181 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each direct dependency to a reviewed, exact version.
- Lock all transitive dependencies using a generated lock file.
- Require cryptographic hashes, such as through
pip install --require-hashes -r requirements.txt. - Configure an explicitly trusted package index and prevent unexpected fallback to untrusted indexes.
- Scan and periodically update locked dependencies through a controlled review process.
- Remove
fpdf2until PDF generation is implemented and the dependency is actually required. - Install dependencies in an isolated, least-privileged virtual environment rather than under an administrator or system account.
