T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Third-Party SDK Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 35
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
markdown Install: `uv add adaptyv-sdk` (falls back to `uv pip install adaptyv-sdk` if no `pyproject.toml` exists)Technical Analysis
The skill directs the agent to install
adaptyv-sdkwithout an exact version constraint, integrity hash, lockfile requirement, or provenance-verification procedure. Consequently, package resolution may select a future release that was not available during this audit.Python package installation can execute package-controlled build and installation logic. If the package distribution or publisher account is compromised, following this instruction could execute attacker-controlled code with the privileges of the user running the agent.
This finding represents supply-chain exposure rather than evidence that the current
adaptyv-sdkpackage is malicious.Attack Path
- An attacker compromises the package publisher account, distribution infrastructure, or a future release of
adaptyv-sdk. - The attacker publishes a malicious version under the expected package name.
- An agent follows the skill instruction and runs
uv add adaptyv-sdkoruv pip install adaptyv-sdk. - The package manager resolves and downloads the malicious release because no reviewed version or hash is required.
- Package-controlled build, installation, or runtime code executes in the agent's environment.
- The malicious code accesses resources available to that process, potentially including project files, environment variables,
.envcontents, and API credentials.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the account running the installation. The accessible scope would be limited by that account's permissions, but could include:
- Reading or modifying files available to the agent.
- Reading environment variable ...[truncated 261 chars]
- An attacker compromises the package publisher account, distribution infrastructure, or a future release of
- Remediation
View remediation
Remediation Suggestions
- Pin
adaptyv-sdkto an exact version that has undergone review, for example:bash uv add 'adaptyv-sdk==X.Y.Z' - Commit and enforce a dependency lockfile so installations resolve to reviewed artifacts.
- Require cryptographic hash verification where supported.
- Verify the package publisher, registry origin, release signatures or attestations, and artifact provenance before installation.
- Perform dependency installation in an isolated, least-privilege virtual environment or container.
- Prevent installation processes from receiving production API credentials unless they are strictly required.
- Use automated dependency scanning and controlled update review before changing the pinned version.
- Pin
