T08 · Insecure Dependencies
- Location
SKILL.md:55- Finding
Unpinned TensorPool Package Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55 and 88
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash # 1. Check tp is installed pip show tensorpool || pip install tensorpoolThe same installation pattern appears again in the prerequisites:
bash pip show tensorpool || pip install tensorpoolTechnical Analysis
The Skill instructs the Agent to install the latest version of
tensorpoolresolved through the environment's configured Python package index. It does not pin a reviewed version, verify a package hash, use a dependency lockfile, or explicitly select a trusted package repository.Python package installation can run package-controlled build and installation logic. Consequently, a compromised package release, compromised transitive dependency, dependency-resolution attack, or maliciously configured package index could result in arbitrary code execution under the account running the Agent.
The audit did not find evidence that the named
tensorpoolpackage is malicious. The vulnerability is the unsafe and non-reproducible installation practice.Attack Path
- An attacker compromises a package release, a transitive dependency, or a configured package index.
- The target environment does not already contain the
tensorpoolpackage. - The Agent follows the Skill and executes
pip install tensorpool. pipresolves and downloads the attacker-controlled package or dependency.- Malicious build or installation logic executes with the Agent process's local privileges.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user running the Agent. This may permit access to local project files, environment variables, API credentials, SSH configuration, and any remote systems accessible by that user. It could also compromise subsequent TensorPool clus ...[truncated 15 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
tensorpoolto a specifically reviewed version. - Use a lockfile or requirements file containing cryptographic hashes.
- Install only from an explicitly approved package index.
- Prefer a pre-provisioned or isolated virtual environment.
- Display the resolved version and source before installation.
- Require user confirmation before installing software that can execute package-controlled build logic.
- Periodically review pinned versions and update them through a controlled dependency-review process.
Example hardened installation pattern:
bash python -m pip install \ --index-url https://pypi.org/simple \ --require-hashes \ -r requirements-tensorpool.lock- Pin
