T08 · Insecure Dependencies
- Location
scripts/ensure_package.py:27- Finding
Import-Time Installation of Unpinned Third-Party Packages
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a Chinese text-correction skill, but it automatically mutates Python environments, installs large unpinned remote dependencies, and can batch-process local files with limited user control.
Install only if you are comfortable with a local skill that can install and update Python packages, download models, inspect GPU state, create persistent logs, and write corrected copies of files or whole folders. Prefer running it in an isolated disposable environment and avoid giving it directories containing sensitive drafts until dependency pinning, logging disclosure, and confirmation controls are improved.
scripts/ensure_package.py:27Import-Time Installation of Unpinned Third-Party Packages
scripts/config.py:29Shared Virtual Environment and Excessive Unpinned Dependency Installation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
venv/
ENV/
env/
.env
# Logs
logs/*.log
A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.
A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.
A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.
A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.
The skill claims to perform Chinese text correction, yet this file immediately mutates the Python environment by reinstalling packaging components. This mismatch is a strong indicator of overprivileged and potentially unsafe behavior because users would not reasonably expect a text-correction skill to alter system dependencies.
The file exposes a generic package-management primitive that can install arbitrary packages from PyPI, git sources, and local archives. In this skill context, that capability is unnecessary and materially increases the risk of supply-chain compromise, arbitrary code execution, and persistent environment tampering.
The skill is presented as a Chinese text-correction capability, but this file acts as an environment bootstrapper that creates virtual environments, inspects hardware, and installs packages. That scope mismatch is dangerous because it hides privileged system-changing behavior behind a benign user-facing description, undermining informed consent and security review.
Audio-processing dependencies such as audio-separator, librosa, and pydub are unrelated to Chinese text correction and significantly expand the skill's capability surface. This discrepancy increases supply-chain risk, attack surface, and the likelihood that the skill is over-privileged or behaving outside user expectations.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
sys.exit(1)
# 传递环境变量防止递归
env = os.environ.copy()
env["RUNNING_IN_VENV"] = "true"
logger.info(f" 当前Python: {sys.executable}")
The script dynamically installs Python packages at runtime using pip, which creates a significant supply-chain and code-execution risk because package resolution and install hooks execute arbitrary third-party code during skill invocation. This is especially dangerous in an agent skill because a simple text-correction request can trigger network access and installation of mutable dependencies without prior review.
The trigger examples are broad enough to overlap with normal conversational editing requests, making accidental invocation more likely. In an agent framework, ambiguous triggering can route benign chat into a tool that reads or modifies files, which creates unnecessary exposure to local data and unintended side effects.
The README explicitly instructs the agent/user to correct all .txt files in a directory, which expands the operational scope from correcting a supplied text or single file to performing bulk actions over user-controlled file paths. In an agent setting, this increases the chance of unintended mass modification of files, especially if triggered from ordinary language without a strong confirmation boundary.
The README describes bulk file correction over a directory but does not prominently warn that this may alter many user files. Without clear notice, preview, backup, or confirmation guidance, users may authorize destructive or hard-to-review changes to large sets of documents.
The skill advertises shell execution, file read/write, and environment interaction but does not declare a restrictive tool scope such as explicit permissions or allowed-tools. In practice, this means a user-invocable skill can perform broader local actions than its manifest communicates, increasing the chance of unintended file access or command execution if the invoked script is altered or behaves unexpectedly.
The trigger phrases are broad enough to match ordinary editing or rewriting requests, which can cause over-activation of a skill that also has shell and file capabilities. Overbroad activation is risky in this context because it increases the chance that a higher-privilege local skill runs when a normal LLM response would have been sufficient.
The activation rules mix precise correction requests with broad intents like polishing, optimizing, and '帮我看看', making invocation ambiguous. In a skill that may touch files and invoke Python scripts, ambiguity makes accidental execution more dangerous because ordinary editorial assistance may route into a privileged local workflow without clear user intent.
The file’s natural-language description explicitly presents the tool as a Chinese text-correction script, and the user-facing argument/help strings throughout the CLI are only in Chinese. Under the policy, forcing a specific language without user opt-in or a clearly documented justification is a natural-language locale policy violation.
The manifest emphasizes correcting Chinese text from direct input, long text, or a provided text file path. However, the module docstring and main logic implement an additional bulk-processing mode for directories, recursively scanning files and creating a sibling output directory with corrected copies.
The script can fetch model artifacts from Hugging Face at runtime, introducing unpinned remote supply-chain risk and unexpected network access for a skill presented as local text correction. If an attacker controls the referenced repository, a dependency path, or the network environment, users may download tampered model files or expose operational metadata through outbound requests.
Installing Python packages at runtime is dangerous because it executes package-manager operations and runs arbitrary install-time code from external package sources inside the user's environment. This greatly expands the trust boundary beyond text correction and creates supply-chain, persistence, and environment-integrity risks if package versions are compromised or unexpectedly changed.
The file header documents a package installation utility rather than text-correction logic, contradicting the skill's stated identity. This inconsistency is suspicious because it suggests hidden or unrelated operational behavior that may escape user scrutiny and increases the chance of unsafe privilege use.
This code invokes pip to forcibly reinstall setuptools and wheel during module execution, mutating the Python environment without explicit user consent. Even though the command is hardcoded, automatic dependency changes at import time can downgrade security-sensitive tooling, break other packages, and create a supply-chain attack surface through package retrieval.
"""专门为老项目(使用 pkg_resources 的 setup.py)修复 setuptools 版本"""
logger.info("🔧 正在修复 setuptools 版本(兼容旧 GitHub 包构建)...")
try:
subprocess.check_call([
sys.executable, "-m", "pip", "install",
"--quiet", "--force-reinstall", "setuptools<=81.2.0", "wheel"
])
The module performs package-management actions immediately upon import by calling fix_setuptools_for_legacy_packages at top level. Import-time side effects are dangerous because merely loading the module triggers network/package operations and environment mutation without an explicit user action or consent boundary.
The function dynamically imports a module name derived from parameters, which can trigger import-time code execution from attacker-controlled or malicious local modules. In this file the import is framed as an installation check, but it still executes arbitrary module top-level code if import_name is influenced by untrusted input.
# 第一步:尝试 import 检查(最快)
try:
parts = import_name.split('.')
mod = __import__(parts[0])
for part in parts[1:]:
mod = getattr(mod, part)
if sub_import:
No suspicious patterns detected.