T08 · Insecure Dependencies
- Location
metadata.json:24- Finding
Unpinned Third-Party Packages Expose the Signing Environment to Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:8-14;metadata.json:24-31
Vulnerability Type: Unpinned and externally retrieved dependencies
Risk Level: MediumVulnerable Code
SKILL.md:8-14:yaml requires: bins: - pip install: - kind: pip package: nostr-profile bins: [] - kind: uv package: nostr-profile bins: []metadata.json:24-31:json "install": { "pip": "nostr-profile" }, "requires": { "python": ">=3.10" }, "dependencies": [ "nostrkey>=0.1.1" ],Technical Analysis
The Skill instructs the platform to install
nostr-profilefrom the public Python package ecosystem without an exact version or integrity hash. Its security-sensitive dependency,nostrkey, also uses an open-ended lower-bound constraint rather than an exact reviewed version.The installed implementation is not included in the audited artifact. Consequently, the behavior reviewed in the documentation and example cannot establish what code will actually execute after package resolution. A future compromised, malicious, or otherwise unsafe package release could be selected without any modification to this Skill.
This is especially sensitive because the dependencies operate in an environment containing Nostr signing credentials. Package installation and import-time code execution can occur with the privileges of the agent process.
Attack Path
- An attacker compromises the publisher account, release pipeline, or distribution artifact for
nostr-profileornostrkey. - The attacker publishes a modified version satisfying the unrestricted dependency declaration.
- A user installs or updates the Skill, and the package manager resolves the attacker-controlled release.
- Malicious installation hooks, import-time logic, or runtime code executes inside the agent environment.
- The malicious dependency reads available credentials, interc ...[truncated 692 chars]
- An attacker compromises the publisher account, release pipeline, or distribution artifact for
- Remediation
View remediation
Remediation Suggestions
- Pin
nostr-profileandnostrkeyto exact, reviewed versions. - Require cryptographic package hashes through a locked requirements file or equivalent package-manager lockfile.
- Audit and vendor the security-critical signing implementation when feasible.
- Use a trusted private package index or explicitly configured approved source rather than relying implicitly on public index resolution.
- Disable unnecessary installation hooks and install packages in an isolated, non-privileged environment.
- Separate package installation from the runtime that has access to signing credentials.
- Introduce automated dependency integrity, provenance, vulnerability, and release-drift checks.
- Pin
