T08 · Insecure Dependencies
- Location
scripts/excel_parser.py:17- Finding
Automatic Runtime Installation of Unpinned Third-Party Packages
- Content
View full analysis
Vulnerability Details
File Location:
scripts/excel_parser.py:17-27, with invocation atscripts/excel_parser.py:41-52
Vulnerability Type: Unsafe runtime dependency installation and supply-chain exposure
Risk Level: MediumComplete Code Snippet
python def install_dependency(package): """Automatically install a missing dependency.""" import subprocess print(f"Installing dependency: {package}") try: subprocess.check_call( [sys.executable, "-m", "pip", "install", package] ) print(f"Dependency {package} installed successfully") return True except subprocess.CalledProcessError as e: print(f"Dependency {package} installation failed: {e}") return FalseThe installation routine is invoked automatically while initializing the parser:
python def _init_engine(self): """Initialize the parsing engine.""" try: from python_calamine import CalamineWorkbook self.calamine = CalamineWorkbook except ImportError: print("Calamine dependency is not installed; attempting automatic installation...") if install_dependency("python-calamine"): try: from python_calamine import CalamineWorkbook self.calamine = CalamineWorkbook except ImportError: raise Exception( "Calamine dependency installation failed; " "install it manually with: pip install python-calamine" ) else: raise Exception( "Calamine dependency installation failed; " "install it manually with: pip install python-calamine" )The primary dependencies are also unconstrained:
text python-dotenv python-calamineTechnical Analysis
Constructing an
ExcelParserobject can launch pip and modify the active Python environment without a separate installation or deployment deci ...[truncated 2634 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove runtime installation
- Do not invoke pip from parsing or library initialization code.
- Raise a clear
ImportErrorthat identifies the missing optional dependency and the explicit installation command.
-
Install dependencies during controlled deployment
- Resolve and install packages in a dedicated build or deployment stage.
- Run the Skill in an isolated virtual environment or container with read-only application dependencies where practical.
-
Pin reviewed versions
- Use exact, reviewed versions in a lock or constraints file.
- Pin both direct and transitive dependencies.
- Review dependency updates before deployment rather than resolving the newest release during execution.
-
Verify package artifacts
- Use a hash-locked requirements file and install with
pip install --require-hashes. - Prefer an approved internal package mirror containing reviewed artifacts.
- Use a hash-locked requirements file and install with
-
Declare fallback packages explicitly
- If
xlrdandopenpyxlare supported runtime dependencies, declare them as pinned optional extras instead of installing them on demand. - For example, provide an
excel-parser-skill[fallback]extra that administrators install explicitly.
- If
-
Apply least privilege and network controls
- Run the parser as an unprivileged account.
- Prevent ordinary parsing workloads from writing to shared Python environments.
- Deny outbound package-index access at runtime when it is unnecessary.
-
