T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party Translation Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code:
bash pip3 install deep-translatorRelated runtime dependency usage in
scripts/digest.py:11,16:python from deep_translator import GoogleTranslator to_chinese = GoogleTranslator(source='auto', target='zh-CN')Technical Analysis
The installation instructions retrieve the latest available version of
deep-translatorwithout a version constraint, cryptographic hash, lockfile, or explicit trusted package index. Consequently, the code reviewed during this audit may differ from the package installed later.Because Python packages can execute code during installation and import, compromise of the upstream package, its maintainer account, or the package distribution channel could introduce arbitrary executable code. The subsequent import in
scripts/digest.pyactivates the installed dependency whenever the digest runs.This is a supply-chain weakness rather than evidence that the current dependency is malicious. No remote scripts or executable payloads are directly downloaded by the project’s own code.
Attack Path
- An attacker compromises the upstream package, a maintainer account, or the package distribution channel.
- The attacker publishes a malicious release under the dependency’s existing package name.
- A user follows the documented
pip3 install deep-translatorinstruction. - Package installation hooks or malicious module initialization execute under the user’s account.
- The malicious dependency can access files, environment variables, and network resources available to that account, including
MOLTBOOK_API_KEYor the documented Moltbook credentials file.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user installing or running the Skill. The accessib ...[truncated 304 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
deep-translatorto a specifically reviewed version rather than installing the latest release. - Record dependencies in a requirements or lock file with cryptographic hashes, for example by using
pip-compile --generate-hashes. - Install with hash enforcement:
bash pip install --require-hashes -r requirements.txt - Explicitly use the trusted package index and disable unintended additional indexes where operationally appropriate.
- Review dependency updates before changing the pinned version and use automated dependency and vulnerability scanning.
- Run the Skill in a dedicated virtual environment under a non-privileged account with access only to the Moltbook credential required for its declared function.
- Pin
