T08 · Insecure Dependencies
- Location
SKILL.md:154- Finding
Unpinned Third-Party Dependencies Installed from Package Registries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:154-157,pptxgenjs.md:9, andpptxgenjs.md:231
Vulnerability Type: Unpinned and globally installed third-party dependencies
Risk Level: MediumVulnerable code snippets:
SKILL.md:154-157bash pip install "markitdown[pptx]" Pillow defusedxml # Node.js: create presentations from scratch npm install -g pptxgenjspptxgenjs.md:9bash C:\Users\Administrator\.workbuddy\binaries\node\versions\node-v20.18.0-win-x64\npm.cmd install -g pptxgenjspptxgenjs.md:231bash npm install -g react react-dom sharp react-iconsTechnical Analysis
The installation commands do not pin package versions or verify package integrity. Consequently, each installation can resolve to a different package release or transitive dependency than the version originally reviewed.
Python packages are installed without hashes or a locked dependency set. The npm commands also use global installation, which modifies a shared Node.js environment and makes the installed modules available beyond the current project. Some npm packages can execute lifecycle scripts during installation, meaning a compromised package release could run code immediately with the privileges of the user performing the installation.
No malicious package or active compromise was identified in the audited project. The vulnerability is the unsafe dependency acquisition model, which leaves the effective code executed during setup dependent on mutable external registries.
Attack Path
- An attacker compromises a named package, one of its transitive dependencies, or the relevant registry account.
- The attacker publishes a malicious version containing installation-time or runtime code.
- A user or agent follows the documented setup instructions after that version becomes the package manager's default resolution.
- Because no exact version, lockfile, or integrity hash is e ...[truncated 1013 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than allowing unconstrained resolution.
- Maintain lockfiles that record the complete transitive dependency graph and integrity metadata.
- For Python, install dependencies in a dedicated virtual environment and require hashes, for example through a fully pinned requirements file used with
pip install --require-hashes. - For Node.js, define dependencies in a project-local
package.json, commitpackage-lock.json, and usenpm ciinstead of global installation. - Avoid
npm install -gunless global installation is strictly necessary. If it is required, pin the exact version and execute installation without administrative privileges. - Review package lifecycle scripts, package ownership changes, and transitive dependency updates before approving version changes.
- Use trusted registries and consider registry allowlisting, dependency scanning, and software composition analysis in the release workflow.
- Run dependency installation and document processing in a restricted environment with minimal filesystem, network, and credential access.
