T08 · Insecure Dependencies
- Location
SKILL.md:162- Finding
Automatic Installation of Unpinned Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 162
Vulnerability Type: Supply-chain risk from automatic, unpinned dependency installation
Risk Level: MediumVulnerable Code Snippet
markdown ### 依赖管理 - pandas / numpy / scipy / matplotlib 未安装时自动 `pip install`,安装到当前 Python 环境 - 图表中文字体缺失时降级为英文标签The relevant instruction states that missing
pandas,numpy,scipy, ormatplotlibpackages must be installed automatically withpipinto the current Python environment.Technical Analysis
The instruction does not specify exact package versions, integrity hashes, a trusted package index, an isolated virtual environment, or an approval step. Consequently, dependency resolution occurs dynamically at execution time and may install versions or transitive dependencies that were never reviewed with the Skill.
Python package installation can execute package-controlled build and installation logic. If the configured package repository, a package release, or a transitive dependency is compromised, malicious code could run with the privileges of the agent process. Installing directly into the current environment can also overwrite or alter dependencies used by unrelated workloads.
The named top-level packages are legitimate and there is no evidence in the project of deliberate dependency confusion or a malicious package source. The finding is therefore an unsafe supply-chain practice rather than proof of malicious intent.
Attack Path
- The Skill is invoked in an environment where one or more named packages are unavailable.
- Following line 162, the agent automatically executes an unpinned
pip install. pipresolves the latest compatible top-level packages and transitive dependencies from its configured indexes.- A compromised package release, dependency, or configured index supplies attacker-controlled installation content.
- Package build or installation logic executes under the agent process identity.
- The paylo ...[truncated 831 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic installation from normal Skill execution and fail safely with a clear list of missing dependencies.
- Require explicit user or administrator approval before modifying any Python environment.
- Define exact direct and transitive dependency versions in a reviewed lock file.
- Record and verify package hashes, using a command such as
pip install --require-hashes -r requirements.txt. - Restrict resolution to an approved HTTPS package index or an internally controlled package mirror.
- Install dependencies in a dedicated virtual environment or immutable container rather than the current shared environment.
- Prevent fallback to untrusted extra indexes and review package-index configuration before installation.
- Scan and periodically update locked dependencies through a controlled review process.
- Run installation and subsequent analysis with a least-privileged identity and restrict unnecessary network and filesystem access.
