T08 · Insecure Dependencies
- Location
scripts/generate_resume_pdf.py:17- Finding
Unpinned Dependency Installation at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_resume_pdf.py, lines 17–27
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: MediumComplete Code Snippet
python try: from reportlab.lib.pagesizes import letter from reportlab.lib.units import inch from reportlab.lib.styles import getSampleStyleSheet, ParagraphStyle from reportlab.lib.enums import TA_LEFT, TA_CENTER from reportlab.platypus import SimpleDocTemplate, Paragraph, Spacer, HRFlowable from reportlab.lib.colors import HexColor except ImportError: print("Installing reportlab...") import subprocess subprocess.check_call(['pip', 'install', 'reportlab', '--break-system-packages', '-q']) from reportlab.lib.pagesizes import letter from reportlab.lib.units import inchTechnical Analysis
When
reportlabcannot be imported, the script automatically invokespipto download and install the package. The dependency has no version constraint, cryptographic hash, lockfile, or explicitly trusted package index. Consequently, the exact code installed and executed can change after the Skill has been audited.Python package installation may execute package-controlled build or installation logic. A compromised package release, dependency, configured package index, package mirror, or network path could therefore cause arbitrary code execution under the privileges of the user running this script.
The
--break-system-packagesoption weakens environment isolation by permitting changes to a system-managed Python installation. This can modify shared dependencies, destabilize other applications, and broaden the impact beyond the resume-generation process.Attack Path
- A user or agent runs the PDF generator in an environment where
reportlabis unavailable or its import fails. - The
ImportErrorhandler invokes the environment-resolvedpipexecutable. pipcontacts its configured package index or mirror ...[truncated 1236 chars]
- A user or agent runs the PDF generator in an environment where
- Remediation
View remediation
Remediation Suggestions
-
Remove automatic package installation from application runtime. If
reportlabis absent, terminate with a clear error explaining how to prepare the environment. -
Declare
reportlabin a dependency manifest and pin it to a reviewed version. -
Use a lockfile or hash-verified requirements file, such as:
text reportlab==REVIEWED_VERSION --hash=sha256:VERIFIED_PACKAGE_HASH -
Install dependencies during a controlled build or deployment phase rather than while processing user requests.
-
Use a dedicated virtual environment or container instead of
--break-system-packages. -
Configure an approved package index or internal mirror and enforce TLS certificate validation.
-
Run dependency vulnerability and provenance checks during CI.
-
Execute PDF generation under a least-privileged account with restricted filesystem and network access.
-
Replace the current handler with fail-closed behavior:
python try: from reportlab.lib.pagesizes import letter # Other required imports except ImportError as exc: raise SystemExit( "Missing required dependency: reportlab. " "Install the pinned project dependencies before running this script." ) from exc
-
