T08 · Insecure Dependencies
- Location
SKILL.md:397- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:397-406
Vulnerability Type: Supply-chain exposure caused by an unpinned dependency
Risk Level: Mediummarkdown | Dependency | Version | Description | |------|------|------| | Python | >= 3.9 | Runtime | | python-pptx | >= 0.6.21 | PPTX file generation | Install the dependency: ```bash pip install python-pptxtext ### Technical Analysis The documented installation command installs `python-pptx` without an exact version, cryptographic hash, lockfile, or explicit trusted package index. The documented `>= 0.6.21` constraint also allows any later release to be selected. Consequently, the code that users execute may differ from the dependency version originally reviewed. If the package distribution channel, a future release, or the user's package-index configuration is compromised, installation could introduce attacker-controlled package code. Python packages can execute code during installation and subsequently when imported by `scripts/ms_investment_deck.py`. The project does not itself retrieve or execute a remote payload, and no evidence indicates that the named dependency is currently malicious. The risk arises from the unsafe, non-reproducible dependency installation procedure. ### Attack Path 1. An attacker compromises a future release of the dependency, its distribution account, or a package index configured in the victim's environment. 2. A user follows the documented `pip install python-pptx` instruction. 3. Package resolution selects the attacker-controlled release because no exact version or hash is enforced. 4. Malicious package code executes during installation or when the application imports `pptx`. 5. The payload runs with the privileges of the user or automation account performing the installation or executing the Skill. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the installin ...[truncated 394 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
python-pptxto a specifically reviewed version rather than using an open-ended minimum version. - Record cryptographic hashes and enforce them with
pip install --require-hashes. - Maintain a committed lockfile or hashed requirements file for reproducible installations.
- Configure installation to use an explicitly trusted package index and disable unintended supplemental indexes where practical.
- Run dependency vulnerability and provenance checks in CI, and review updates before changing the pinned version.
- Install and run the Skill in a least-privileged virtual environment or container without unnecessary credentials.
Example hardened requirements entry:
text python-pptx==<reviewed-version> \ --hash=sha256:<verified-package-hash>Example installation command:
bash python -m pip install --require-hashes -r requirements.txt- Pin
