T08 · Insecure Dependencies
- Location
export_deps.py:19- Finding
Unpinned Dependency Is Downloaded and Installed at Runtime
- Content
View full analysis
bool: if package in _INSTALL_ATTEMPTED: return False _INSTALL_ATTEMPTED.add(package) commands: list[list[str]] = [] uv = shutil.which("uv") if uv: commands.append([uv, "pip", "install", package, "-q"]) commands.append([sys.executable, "-m", "pip", "install", package, "-q"]) for cmd in commands: try: proc = subprocess.run( cmd, timeout=180, capture_output=True, text=True, ) if proc.returncode == 0: importlib.invalidate_caches() return True except (OSError, subprocess.TimeoutExpired): continue return False def ensure_openpyxl() -> Tuple[bool, str | None]: try: import openpyxl # noqa: F401 return True, None except ImportError: if _try_install("openpyxl"): try: import openpyxl # noqa: F401 return True, None except ImportError: pass ``` ### Technical Analysis When `openpyxl` is unavailable, the skill automatically invokes `uv pip install openpyxl` or `python -m pip install openpyxl`. The package has no pinned version, integrity hash, trusted-index restriction, or prior administrative approval. Although the package name is hardcoded and therefore is not directly vulnerable to shell injection, installation still downloads executable Python package content from the package index configured in the runtime environment. Package installation and subsequent import may execute package-controlled setup, build, or import-time code with the privileges of the skill process. This creates a supply-chain execution path whose ...[truncated 1283 chars]- Remediation
View remediation
