T08 · Insecure Dependencies
- Location
SKILL.md:171- Finding
Unpinned Third-Party Package Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 171–174
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
bash pip install funclip pip install openai-whisperTechnical Analysis
The installation instructions retrieve mutable third-party packages from the user's configured Python package index without specifying reviewed versions, package hashes, a lockfile, or a trusted index URL. Consequently, the code installed by these commands may differ between executions and cannot be verified against a known-good artifact.
This creates exposure to compromised upstream releases, package-index substitution, dependency confusion involving transitive packages, or a malicious package served by an untrusted configured mirror. A malicious source distribution or build dependency may execute code during package installation, while malicious installed modules may execute when subsequently imported.
Attack Path
- An attacker compromises an upstream package, one of its transitive dependencies, or a package index used by the victim.
- The attacker publishes or serves a malicious release under a dependency name resolved by pip.
- A user follows the Skill documentation and runs one of the unpinned installation commands.
- Pip resolves the mutable dependency graph and downloads the attacker-controlled release.
- Malicious code executes during the package build or later when the installed package is imported and used.
Impact Assessment
Successful exploitation can execute code with the privileges of the user performing the installation or running the installed package. This may permit access to that user's files, environment variables, credentials available to the process, and the active Python environment. If installation is performed with elevated privileges, the impact can extend to system-wide Python packages and files accessible to th ...[truncated 22 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed, exact version.
- Maintain a lockfile that also fixes all transitive dependency versions.
- Require package hashes, such as through a hash-locked requirements file and pip's
--require-hashesoption. - Explicitly document and enforce a trusted package index rather than relying on arbitrary user or environment configuration.
- Install dependencies in an isolated virtual environment under a non-privileged account.
- Review package provenance, release signatures where available, build dependencies, and transitive dependencies before updating pins.
- Add automated dependency vulnerability and integrity scanning to the release process.
