T08 · Insecure Dependencies
- Location
SKILL.md:157- Finding
Unverified Executable Downloads and Unpinned Runtime Dependencies
- Content
View full analysis
\llama.cpp" $zip = "$env:TEMP\llama-vulkan.zip" $url = "https://github.com/ggml-org/llama.cpp/releases/download/$tag/llama-$tag-bin-win-vulkan-x64.zip" Write-Host "Downloading llama.cpp $tag ..." Invoke-WebRequest -Uri $url -OutFile $zip New-Item -ItemType Directory -Force -Path $llamaDir | Out-Null Expand-Archive $zip -DestinationPath $llamaDir -Force Remove-Item $zip Write-Host "LLAMA_INSTALL=DONE" ``` ```powershell $mf = "$env:TEMP\Miniforge3-Windows-x86_64.exe" Invoke-WebRequest ` -Uri "https://github.com/conda-forge/miniforge/releases/latest/download/Miniforge3-Windows-x86_64.exe" ` -OutFile $mf Start-Process $mf -ArgumentList "/S /D=$env:USERPROFILE\miniforge3" -Wait Remove-Item $mf $env:PYTHON_EXE = "$env:USERPROFILE\miniforge3\python.exe" & $env:PYTHON_EXE --version Write-Host "PYTHON_OK" ``` ```powershell & $env:PYTHON_EXE -m pip install huggingface_hub -q ``` ```powershell & $env:PYTHON_EXE -m pip install modelscope -q ``` ### Technical Analysis The Skill downloads native software and installs Python packages at runtime without validating cryptographic hashes or digital signatures. The llama.cpp archive uses a fixed release tag by default, but no SHA-256 digest or Authenticode validation is performed before its contents are extracted and `llama-cli.exe` is subsequently executed. The Miniforge installer is obtained through a mutable `latest` URL and is immediately executed in silent mode. Consequently, the effective installer can change after the Skill has been reviewed. The `huggingface_hub` and `modelscope` packages are also installed without ex ...[truncated 2040 chars]- Remediation
View remediation
