T08 · Insecure Dependencies
- Location
SKILL.md:215- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 215
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
python # Requires: pip install pytesseract pdf2image import pytesseract from pdf2image import convert_from_pathTechnical Analysis
The documentation directs users to install third-party packages without version constraints, cryptographic hashes, a lock file, or an explicitly trusted package index. Consequently, package names may resolve to mutable releases and uncontrolled transitive dependencies from the user's configured Python package index.
Python package installation may execute package build or installation logic. A compromised future release, compromised transitive dependency, or package substitution through an untrusted index could therefore cause attacker-controlled code to run. The project also imports additional third-party libraries but does not provide a dependency manifest that records reviewed versions and artifact hashes.
No evidence indicates that
pytesseractorpdf2imageis currently malicious. This finding concerns the unsafe and non-reproducible installation method rather than confirmed malicious package content.Attack Path
- A user follows the instruction in
SKILL.mdand runspip install pytesseract pdf2image. - pip queries the package index configured in the user's environment.
- The resolver selects current package releases and transitive dependencies without validating them against project-approved versions or hashes.
- A compromised release, malicious transitive dependency, or substituted distribution is downloaded.
- Attacker-controlled code executes during installation or when the dependency is subsequently imported by the PDF-processing workflow.
Impact Assessment
Malicious dependency code would execute with the privileges of the user installing or running the Skill. It could potentiall ...[truncated 464 chars]
- A user follows the instruction in
- Remediation
View remediation
Remediation Suggestions
-
Add a reviewed dependency manifest with exact versions for all third-party Python dependencies.
-
Generate and record cryptographic hashes for every direct and transitive distribution.
-
Require hash verification during installation, for example:
bash python -m pip install --require-hashes -r requirements.txt -
Use a lock-generation process that resolves transitive dependencies reproducibly.
-
Document the trusted package index and prevent fallback to uncontrolled extra indexes.
-
Prefer prebuilt, reviewed artifacts and avoid source builds where practical.
-
Automate dependency vulnerability scanning and periodic review before updating pinned versions.
-
Perform installation in an isolated virtual environment under a non-privileged account.
-
