T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:215-217
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
python # Requires: pip install pytesseract pdf2image import pytesseract from pdf2image import convert_from_pathTechnical Analysis
The installation guidance uses
pip install pytesseract pdf2imagewithout pinned versions, cryptographic hashes, a dependency lockfile, or an explicitly trusted package index. Package resolution therefore depends on mutable external package-index state at installation time.The named packages are established packages rather than apparent typosquatting attempts, and the project does not automatically execute this installation command. Nevertheless, an agent following the documented workflow could install versions that differ from those reviewed by the project author. If a package release, transitive dependency, configured package index, or package-resolution environment is compromised, installation or subsequent import may execute attacker-controlled code.
Attack Path
- A user requests OCR processing of a scanned PDF.
- The agent follows the installation instruction in
SKILL.md. pipresolves the latest compatible versions from its configured indexes because no versions or hashes are specified.- An attacker compromises a resolved package or transitive dependency, or controls a higher-priority configured package index.
- The malicious component executes during installation or when the package is imported by the OCR workflow.
- The component gains access to the files, environment variables, network access, and operating-system permissions available to the account running the agent.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user or service account running
pipand the PDF workflow. The resulting scope may include access to PD ...[truncated 390 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version, for example:
bash python -m pip install --index-url https://pypi.org/simple pytesseract==REVIEWED_VERSION pdf2image==REVIEWED_VERSION - Commit a requirements or lock file that also constrains transitive dependencies.
- Generate and verify cryptographic hashes, then install with
--require-hashes. - Use an approved internal package mirror or explicitly specify the trusted official index to reduce dependency-confusion exposure.
- Install packages inside a dedicated virtual environment or sandbox under an unprivileged account.
- Disable unnecessary network and filesystem access while processing untrusted PDFs.
- Add automated dependency vulnerability and integrity scanning to the release process.
- Document tested dependency versions and periodically update them through a controlled review process.
- Pin every direct dependency to a reviewed version, for example:
