T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Runtime Installation of a Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20 and 33–34
Vulnerability Type: Unpinned dependency installation
Risk Level: MediumVulnerable Instructions
markdown **Runtime requirement**: The `python-docx` library is required (automatically checked and installed before execution). ### Issue 3: python-docx is not preinstalled **Solution**: Before running the script, call `runtime.apply_sync` to install `python-docx`.Technical Analysis
The Skill directs the Agent to install
python-docxdynamically, but it does not specify an audited version, an integrity hash, a lock file, or a trusted package source. Consequently, dependency resolution can change over time and may retrieve a compromised, malicious, or incompatible release.The audited Python scripts do not themselves execute an installer. The risk arises from the installation instructions that an Agent is expected to follow before invoking the scripts.
Attack Path
- An attacker compromises the relevant package distribution account or upstream package source.
- Alternatively, the runtime is configured to use an attacker-controlled or compromised package mirror.
- The Agent loads the Skill and follows its instruction to install the unpinned
python-docxpackage. - The package manager resolves the dependency to the attacker-controlled release.
- Package installation or subsequent import executes malicious package code with the privileges of the Agent runtime.
Impact Assessment
Successful exploitation could execute arbitrary code under the runtime user's privileges. Depending on the execution environment, this may permit access to patent documents, generated reports, environment variables, workspace files, and other resources available to the Agent process.
No evidence shows that the currently referenced package or generated artifacts are malicious. This finding concerns the unsafe and non-reproducible dependency acquisition process.
- Remediation
View remediation
Remediation Suggestions
- Pin
python-docxto a reviewed exact version in a requirements or lock file. - Include cryptographic hashes and require hash verification during installation.
- Restrict package retrieval to an explicitly configured, trusted repository.
- Prefer a prebuilt environment containing reviewed dependencies instead of installing packages dynamically during Skill execution.
- Audit transitive dependencies and update them through a controlled review process.
- Fail closed if the installed package version or hash does not match the approved dependency manifest.
- Pin
