T08 · Insecure Dependencies
- Location
SKILL.md:144- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:144
Additional Locations:README.md:35,README_CN.md:33,CONTRIBUTING.md:52
Vulnerability Type: Unpinned third-party dependencies and missing integrity verification
Risk Level: MediumVulnerable code:
bash pip install python-docx matplotlib pandas numpy openpyxlTechnical Analysis
The documented installation command installs multiple third-party packages without fixed versions or cryptographic hashes. Consequently, package resolution depends on mutable releases available through the user's configured Python package index at installation time.
If a named package, one of its transitive dependencies, or the configured package index is compromised, users may install attacker-controlled code. Malicious Python packages can execute code during installation or when imported by the report-generation scripts. The project processes student assessment information, so compromise could expose sensitive educational data available to the running process.
This finding is limited to dependency integrity and reproducibility. The audited project scripts themselves contain no confirmed malicious payload, remote code retrieval, shell execution, credential access, or persistence behavior.
Attack Path
- An attacker compromises a listed package, a transitive dependency, or a package source configured in the victim's environment.
- The attacker publishes a malicious release that satisfies the unconstrained dependency request.
- A user follows the documented
pip installcommand. pipresolves and installs the malicious or compromised release because no approved version or hash is enforced.- Attacker-controlled code executes during package installation or when the dependency is imported by a project script.
- The payload operates with the privileges of the user running
pipor the report-generation process and may access student data and files available to that account.
...[truncated 694 chars]
- Remediation
View remediation
Remediation Suggestions
- Create a dependency lock file containing reviewed, exact versions for every direct and transitive dependency.
- Generate and record cryptographic hashes for all approved distributions.
- Require hash verification during installation, for example:
bash python -m pip install --require-hashes -r requirements.txt- Use compatible-release constraints only in source dependency declarations; deploy from a fully resolved lock file.
- Install dependencies inside a dedicated virtual environment under a non-privileged account.
- Explicitly configure a trusted package index and avoid unreviewed mirrors or fallback indexes.
- Add automated dependency vulnerability and provenance scanning to continuous integration.
- Regularly review and deliberately update locked versions rather than resolving the latest releases at each installation.
- Update all affected documentation locations so they consistently direct users to the verified lock file.
