T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Dependency Installation Instruction
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 215–218
Vulnerability Type: Unpinned dependencies resolved from a mutable package registry
Risk Level: MediumVulnerable Code Snippet:
python # Requires: pip install pytesseract pdf2image import pytesseract from pdf2image import convert_from_pathTechnical Analysis
The OCR example instructs users or agents to install
pytesseractandpdf2imagewithout exact version constraints, package hashes, a lockfile, or an explicitly trusted package index. Consequently, the installed code is determined by the state and configuration of the package registry at installation time rather than by the audited project contents.Although the referenced package names are not inherently malicious, an unpinned installation may retrieve newly released, compromised, or otherwise incompatible package versions and their transitive dependencies. Python packages can execute code during installation and subsequently when imported. This creates a supply-chain trust boundary that is not controlled by the project.
Attack Path
- A user requests OCR processing of a scanned PDF.
- A user or agent follows the instruction in
SKILL.mdand runspip install pytesseract pdf2image. pipresolves the latest acceptable packages and transitive dependencies from the environment's configured index.- If the index, a package release, or a transitive dependency has been compromised, attacker-controlled code is installed.
- Malicious code may execute during installation or when the documented imports are evaluated.
- The code runs with the permissions of the account performing the installation or invoking the OCR workflow.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the invoking user's privileges. Depending on that account's permissions and environment, the affected scope could include accessible project files, proc ...[truncated 386 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the inline unpinned installation command with a reviewed dependency manifest containing exact versions.
- Generate and verify cryptographic hashes for every direct and transitive dependency, then require hash validation during installation, for example with
pip install --require-hashes -r requirements.txt. - Use a lockfile generated from a controlled build process and update it through reviewed dependency-upgrade changes.
- Explicitly configure an approved package index rather than relying on arbitrary environment-level index settings.
- Run dependency installation and PDF processing in an isolated virtual environment or restricted container using a non-privileged account.
- Add automated dependency vulnerability and integrity scanning to the maintenance workflow.
- Document the required external OCR executable separately, including trusted installation sources and supported versions.
