T08 · Insecure Dependencies
- Location
SKILL.md:203- Finding
Unpinned Automatic Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 203 and 355
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Vulnerable Snippets
Line 203:
markdown 1. 调用 `runtime.apply_sync` 确保依赖已安装(ezdxf、matplotlib、numpy)Line 355:
markdown | 依赖安装 | `runtime.apply_sync` | ✅ 已验证 |The first instruction requires the runtime to install
ezdxf,matplotlib, andnumpy. The second identifiesruntime.apply_syncas the dependency-installation mechanism and claims that it has been verified.Technical Analysis
The drawing workflow directs the agent to install third-party packages automatically, but it does not specify exact versions, integrity hashes, a lockfile, an approved package repository, or any other reproducible provenance control.
Because
SKILL.mddefines actions the agent is expected to perform at runtime, invokingruntime.apply_syncmay resolve package versions and transitive dependencies from the runtime's configured package source. The packages named in this file are legitimate packages, and the audit found no evidence that they are currently malicious. The vulnerability arises from uncontrolled future dependency resolution rather than from a confirmed malicious package.A compromised package release, transitive dependency, package index, or dependency-resolution configuration could introduce attacker-controlled code. Depending on the package manager and runtime behavior, such code could execute during installation or when the generated Python drawing script imports the affected package. Marking the installation mechanism as “verified” does not provide package-level integrity or reproducibility.
Attack Path
- An attacker compromises a named package, one of its transitive dependencies, or a package repository used by the runtime.
- A user invokes the patent-drawing workflow.
- The Skill directs the agent to call
runtime.apply_syncto install the dependencies. - The runtim ...[truncated 1008 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact reviewed version.
- Capture and pin all transitive dependencies in a committed lockfile.
- Require cryptographic hashes for downloaded distributions and reject artifacts whose hashes do not match.
- Restrict dependency resolution to an approved, authenticated package repository or internally mirrored registry.
- Run package installation and drawing generation in an isolated, least-privilege environment without unnecessary credentials or network access.
- Separate dependency provisioning from normal Skill execution. Build and review a fixed environment in advance instead of installing packages for every invocation.
- Require explicit user approval before making environment changes when pre-provisioning is impossible.
- Scan dependency artifacts and review provenance before updating pinned versions.
- Avoid or disable package installation scripts where the selected tooling and packages permit it.
- Replace the unsupported “verified” assertion with documented verification details, including versions, hashes, source repository, review date, and update procedure.
