T08 · Insecure Dependencies
- Location
scripts/setup_and_verify.py:17- Finding
Automatic Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup_and_verify.py:17-21
Additional Location:SKILL.md:14
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: MediumThe default setup workflow installs the latest version of
mootdxand its transitive dependencies without version constraints, integrity hashes, a lockfile, or an explicitly trusted package index.python def install(): """Install mootdx via pip.""" print("Installing mootdx...") subprocess.check_call([sys.executable, "-m", "pip", "install", "mootdx"]) print()The same behavior is presented in the installation documentation:
bash pip install mootdxTechnical Analysis
Python packages can execute package-controlled code during installation and later when imported. Because the command requests an unpinned package name, the artifact installed by this script can change over time without any corresponding change to the audited project.
Pip also inherits package-index and resolver configuration from the execution environment. The script does not:
- Pin a reviewed
mootdxversion. - Lock or constrain transitive dependency versions.
- Verify package artifacts using cryptographic hashes.
- Select an explicitly trusted package index.
- Separate dependency installation from the default verification workflow.
Consequently, a compromised upstream release, compromised transitive dependency, or attacker-controlled package index configured in the environment could supply code that was not part of this audit.
Attack Path
- An attacker compromises a future
mootdxrelease, one of its transitive dependencies, or a package index used by the target environment. - A user follows the documented default command:
bash python scripts/setup_and_verify.py - Because
--checkwas not supplied,main()invokesinstall(). - The scrip ...[truncated 1325 chars]
- Pin a reviewed
- Remediation
View remediation
Remediation Suggestions
- Pin
mootdxand all transitive dependencies to versions that have been reviewed and tested. - Maintain dependencies in a lockfile or requirements file generated with a tool such as
pip-compile. - Require cryptographic hashes for every resolved artifact, for example:
bash python -m pip install --require-hashes -r requirements.txt - Configure an explicitly trusted package index rather than silently inheriting arbitrary index configuration.
- Review package provenance and monitor pinned dependencies for security advisories.
- Remove automatic installation from the default verification path. Require an explicit option such as
--installbefore modifying the Python environment. - Run installation in an isolated virtual environment under a non-privileged account.
- Consider changing the implementation to:
python subprocess.check_call([ sys.executable, "-m", "pip", "install", "--require-hashes", "-r", "requirements.txt", ]) - Update
SKILL.mdso the documented installation process uses the same pinned and hash-verified dependency manifest.
- Pin
