T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned and Unauditable Third-Party Package Installation
- Content
View full analysis
**Install:** `pip install sense-music` then `from sense_music import analyze` ``` `metadata.json:8`: ```json "install": "pip install sense-music", ``` `metadata.json:19-23`: ```json "dependencies": { "librosa": ">=0.10", "matplotlib": ">=3.7", "Pillow": ">=10.0", "numpy": ">=1.24", "openai-whisper": ">=20231117" }, ``` ### Technical Analysis The skill installs `sense-music` from the public Python package index without an exact version or integrity hash. Its listed dependencies also use open-ended lower-bound constraints, allowing later package versions to be selected at installation time. The audited project contains only documentation, metadata, and a six-line usage example. It does not contain the implementation of the imported `sense_music` package. Therefore, the actual code executed by installation and import cannot be audited from this artifact, and the documented SSRF, path-traversal, XSS, and resource-limit protections cannot be independently verified here. Because package resolution is mutable, two installations reviewed at different times can retrieve different code. A compromise of the `sense-music` distribution, one of its dependencies, or the relevant package-publishing accounts could introduce code that was not present during this review. ### Attack Path 1. An attacker compromises a maintainer or package-publishing account for `sense-music` or one of its dependencies and publishes a malicious compatible release. 2. An operator follows `pip install sense-music`, or the skill manager processes the unpinned `uv` installation declaration. 3. The package resolve ...[truncated 1070 chars]- Remediation
View remediation
