T08 · Insecure Dependencies
- Location
package.json:35- Finding
Unpinned and Ecosystem-Mismatched Dependency Declarations
- Content
View full analysis
=1.0.0" }, "devDependencies": { "pytest": ">=7.0.0" }, "engines": { "python": ">=3.7" } ``` The installation guidance in `SKILL.md`, lines 408-412, also installs Python dependencies without version pins or integrity verification: ```markdown **Install dependencies**: ```bash pip install python-docx pytest ``` ``` ### Technical Analysis The project declares `python-docx` and `pytest`, which are Python packages, inside the npm `dependencies` and `devDependencies` fields of `package.json`. An npm-based installer may therefore resolve packages with these names from the npm registry rather than installing the intended packages from the Python Package Index. Such same-name packages are distinct artifacts and may contain unrelated or hostile installation behavior. The version constraints use open-ended minimum ranges (`>=1.0.0` and `>=7.0.0`). The documented pip command is even less restrictive and does not verify package hashes. No dependency lockfile or hash-pinned requirements file was identified during the audit. Consequently, future or compromised releases can be selected without a corresponding source-code review. This does not prove that the currently resolved packages are malicious. It creates a supply-chain exposure in which package identity and version selection depend on the installer and mutable external registries. ### Attack Path 1. A user or plugin manager installs the project and processes `package.json` as an npm manifest. 2. The installer attempts to resolve npm packages named `python-docx` and `pytest`, rather than the intended Python packages. 3. An attacker publishes, compromises, or gains control of a matching npm package or a later release that satisfies the unrestricted constrain ...[truncated 1018 chars]- Remediation
View remediation
\ --hash=sha256: ``` Place `pytest` in a separate development requirements group and pin it in the same manner. 4. Generate and commit a lockfile using a controlled process such as `pip-tools`, Poetry, or uv. Review dependency updates before regenerating the lockfile. 5. Update `SKILL.md` so installation uses the locked dependency source rather than: ```bash pip install python-docx pytest ``` 6. Configure package managers to use approved registries and enforce integrity verification in CI and release workflows. 7. Add automated checks that reject Python dependency names in npm dependency sections and reject unpinned production dependencies. ]]>
