T08 · Insecure Dependencies
- Location
SKILL.md:102- Finding
Unpinned Global and System-Level Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:102-106,SKILL.md:214-217,references/docx-formatting.md:8,references/cccd-ocr-guide.md:24-30,scripts/cccd-ocr.py:23-35
Vulnerability Type: Supply-chain exposure through unpinned dependencies and unsafe package installation
Risk Level: MediumVulnerable Code
SKILL.md:102-106:bash ## Bước 1: Cài đặt môi trường # Cài docx-js (thư viện tạo file .docx) npm install -g docxSKILL.md:214-217:bash ### Cài đặt (1 lần) pip install easyocr opencv-python --break-system-packagesreferences/cccd-ocr-guide.md:24-30:bash ## Cài đặt pip install easyocr opencv-python --break-system-packages Lần đầu chạy sẽ tự tải model tiếng Việt (~100MB).scripts/cccd-ocr.py:23-35:python def check_deps(): missing = [] try: import easyocr except ImportError: missing.append("easyocr") try: import cv2 except ImportError: missing.append("opencv-python") if missing: print("Thieu thu vien. Chay lenh:") print(f" pip install {' '.join(missing)} --break-system-packages")Technical Analysis
The documented installation commands retrieve the latest available versions of
docx,easyocr, andopencv-pythonwithout version constraints, lockfiles, package hashes, or artifact verification. The npm package is installed globally, expanding the scope of filesystem changes beyond this project. The Python command uses--break-system-packages, bypassing protections intended to prevent pip from modifying an externally managed Python environment.EasyOCR initialization also downloads a language model during first use. The project does not pin or verify the model version, source, checksum, or signature. Consequently, the effective runtime components can change after the skill package itself has been audited.
This is a supply-c ...[truncated 1624 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin exact reviewed package versions rather than resolving the latest versions:
bash npm install --save-exact docx@REVIEWED_VERSION python -m pip install easyocr==REVIEWED_VERSION opencv-python==REVIEWED_VERSION - Add and commit appropriate lockfiles, such as
package-lock.jsonand a hash-pinned Python requirements file. - Require integrity verification with Python package hashes and verified npm lockfile integrity metadata.
- Install dependencies inside a dedicated virtual environment or disposable container. Remove
--break-system-packages. - Use a project-local npm dependency instead of
npm install -g. - Disable automatic model downloads in production where possible. Pre-fetch a reviewed model from an approved source and verify its cryptographic checksum before use.
- Run package installation and OCR processing under a restricted, non-privileged account with limited filesystem and network access.
- Add dependency scanning and periodic review of direct and transitive dependencies.
- Pin exact reviewed package versions rather than resolving the latest versions:
