T08 · Insecure Dependencies
- Location
rules/install.md:8- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
rules/install.md:8-13
Additional Locations:SKILL.md:5,SKILL.md:27,README.md:16-21,skill.json:20-24
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code:
markdown ## Quick Install ```bash pip install anakin-clitext The package is also declared without a version constraint: ```json "install": { "pip": { "package": "anakin-cli", "bins": ["anakin"] } }Technical Analysis
The Skill directs the agent to install the latest available release of
anakin-clifrom PyPI without an exact version, cryptographic hash, lock file, or other integrity control. The executable implementation is not included in the audited project, so its runtime behavior cannot be verified from this artifact.Because package resolution is mutable, the code installed by the same command can change after the Skill has been reviewed. If the legitimate package account, publishing credentials, or distribution channel is compromised, a malicious release could execute installation or runtime code with the privileges of the user running the agent.
This finding does not establish that the current PyPI package is malicious. It identifies an unsafe dependency acquisition process that permits an upstream compromise to affect users without any change to the audited Skill.
Attack Path
- An attacker compromises the
anakin-clipackage publishing account or its release pipeline. - The attacker publishes a malicious version under the legitimate package name.
- A user or agent follows the Skill instructions and executes
pip install anakin-cli. - Pip resolves the attacker-controlled release because no trusted version or hash is specified.
- Malicious installation or runtime code executes under the agent user's account.
- The code may access data available to that account, including envi ...[truncated 496 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
anakin-clito a specific version that has been reviewed, for example:bash python -m pip install "anakin-cli==X.Y.Z" - Publish a requirements file containing approved hashes and install it with:
bash python -m pip install --require-hashes -r requirements.txt - Update both
SKILL.mdmetadata andskill.jsonso automated installation uses the same approved version. - Install the CLI in a dedicated virtual environment rather than the agent's global Python environment.
- Review new releases before changing the pinned version, and document the dependency update and verification process.
- Where supported, verify package provenance, signatures, and publisher identity before installation.
- Pin
