T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Dependencies Permit Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15-18,SKILL.md:410,SKILL.md:413,SKILL.md:440, andREADME.md:14-17
Vulnerability Type: Unpinned and unverified third-party package installation
Risk Level: MediumVulnerable Code
SKILL.md:15-18:yaml install: - id: install-markitdown kind: exec command: pip3 install 'markitdown[all]'SKILL.md:410:bash pip install 'markitdown[all]'SKILL.md:413:bash conda install -c conda-forge markitdownSKILL.md:440:bash pip install markitdown-mcpREADME.md:14-17:bash pip3 install 'markitdown[all]'Technical Analysis
The Skill installs
markitdown, all packages selected by itsallextra, and the optionalmarkitdown-mcppackage without fixed versions or integrity hashes. Consequently, the installed code is determined by mutable package-repository state at installation time rather than by the version reviewed during this audit.The
markitdown[all]specification also expands the supply-chain and parser attack surface by installing optional transitive dependencies. None of the installation instructions use a lock file, hash verification, an explicitly trusted package index, or an isolated execution policy.The metadata installation command is particularly relevant because a compatible Skill framework may execute it as part of automated Skill setup. Package installation can execute package build hooks, and installed packages later execute within the MarkItDown command, Python API, or MCP server process.
This finding does not establish that the current upstream packages are malicious. The vulnerability is the absence of controls that bind installation to reviewed artifacts.
Attack Path
- An attacker compromises the publishing account, build pipeline, distribution artifact, or transitive dependency of one of the referenced packages.
- The attacker publishes a malicious version that satisfies the unrestricted package ...[truncated 1341 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version:
bash python3 -m pip install 'markitdown[all]==REVIEWED_VERSION' python3 -m pip install 'markitdown-mcp==REVIEWED_VERSION'-
Generate a lock file containing exact versions for all transitive dependencies. Review and update it through a controlled dependency-update process.
-
Require cryptographic hashes for downloaded artifacts, for example with a hash-locked requirements file:
bash python3 -m pip install --require-hashes -r requirements.lock-
Avoid the broad
allextra unless every optional converter is required. Install only the format-specific extras needed by the Skill to reduce the dependency and parser attack surface. -
Configure an explicit trusted package index or an internally controlled package mirror. Do not allow fallback to untrusted or unintended indexes.
-
Install packages inside a dedicated virtual environment or container rather than into the system Python environment:
bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.lock-
Run document conversion and the MCP server as a non-privileged account with restricted filesystem and network access. Do not install or invoke these components as root.
-
Add automated dependency scanning, provenance verification, and periodic review of pinned updates. Recreate and test the lock file whenever an approved dependency version changes.
-
Make the installation policy consistent across
SKILL.mdandREADME.mdso users cannot bypass the hardened process by following alternate instructions.
