T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Dependency Installation and Automatic Self-Update
- Content
View full analysis
/dev/null; then echo "yt-dlp not found, installing..." pip install -q yt-dlp || pip3 install -q yt-dlp fi yt-dlp -U --quiet 2>/dev/null || true ``` ### Technical Analysis The Skill automatically installs the latest available `yt-dlp` package from the user's configured Python package index without pinning a reviewed version or validating a cryptographic hash. It then invokes `yt-dlp -U`, allowing the executable to update itself whenever the Skill runs. Consequently, the code executed by the Skill can change after the Skill has been reviewed. The effective source of the installed package also depends on environment-level package-index configuration, including `PIP_INDEX_URL`, `PIP_EXTRA_INDEX_URL`, and user-level pip configuration. A compromised package repository, malicious package release, or attacker-controlled package source could therefore cause arbitrary package code to run under the Agent's operating-system account. Suppressing update errors and continuing with `|| true` also prevents users from noticing that update behavior failed or behaved unexpectedly. ### Attack Path 1. An attacker compromises the configured package source, publishes a malicious upstream release, or causes the environment to use an attacker-controlled Python package index. 2. The Skill is invoked on a system where `yt-dlp` is missing, or its unconditional update command is executed against an existing installation. 3. `pip install yt-dlp` retrieves an unpinned package, or `yt-dlp -U` retrieves an unreviewed update. 4. Installation hooks or the resulting executable run attacker-controlled code. 5. The malicious code executes with the permissions of the Agent process and can access files, credentials, network resources, and other data available t ...[truncated 585 chars]- Remediation
View remediation
