T08 · Insecure Dependencies
- Location
src/main.py:4- Finding
Unpinned Runtime Dependencies Create a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
src/main.py:4-12
Vulnerability Type: Unpinned automatically installed third-party dependencies
Risk Level: MediumVulnerable Code
python # /// script # requires-python = ">=3.12" # dependencies = [ # "pypdf", # "pdfplumber", # "reportlab", # "python-docx", # "edge-tts", # "pillow", # ] # ///The project wrapper automatically invokes this dependency-enabled script:
bash exec uv run "$SKILL_DIR/src/main.py" "$@"The documented behavior confirms that dependency resolution and installation occur at runtime:
markdown - `uv run` reads the inline `# /// script` dependency block in `main.py` and auto-installs Python packages in an isolated environment — no pip install or venv setup needed.Technical Analysis
All six Python dependencies are declared without exact versions. No reviewed lockfile or integrity hashes are present in the audited project. Consequently,
uv runmay resolve and install package releases that were not part of this audit.Isolation of the package environment does not prevent malicious package code from inheriting the skill process's effective filesystem and network permissions. Imported dependencies execute in the same Python process as the toolkit. A compromised upstream release, package-maintainer account, transitive dependency, or package-index response could therefore introduce code execution after the skill itself has been reviewed.
The relevant execution chain spans:
src/main.py:4-12, where unconstrained dependencies are declared.pdf-toolkit.sh:6, whereuv runinitiates dependency resolution.SKILL.md:172, where automatic installation is explicitly documented.
Attack Path
- An attacker compromises an upstream dependency, one of its transitive dependencies, its publisher account, or the package distribution channel.
- A malicious version remains compatible with the unconstrained dependency declarations.
- A user in ...[truncated 1144 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than using unconstrained package names.
- Generate and commit a
uv.lockfile containing the complete resolved dependency graph. - Execute with locked or frozen dependency resolution so runtime execution fails instead of silently selecting newer releases.
- Use package hashes or another artifact-integrity verification mechanism where supported.
- Perform dependency updates through a controlled review process that includes vulnerability scanning, changelog review, and regression testing.
- Configure trusted package indexes explicitly and avoid fallback to untrusted or unexpected package sources.
- Consider prebuilding and distributing a reviewed environment or immutable artifact so normal skill invocation does not install code from the network.
- Run the skill with least privilege and restrict filesystem and network access to reduce the impact of a compromised dependency.
