T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unbounded Stripe SDK Dependency Exposes the Skill to Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15-17,scripts/list_products.py:19-25, andscripts/create_checkout_session.py:19-25
Vulnerability Type: Unbounded third-party dependency
Risk Level: MediumVulnerable Code
SKILL.md:15-17:yaml install: uv: - stripe>=10.0.0scripts/list_products.py:19-25:python { "error": { "type": "dependency_error", "message": "The 'stripe' Python package is not installed. Install it with: pip install 'stripe>=10.0.0'", } }scripts/create_checkout_session.py:19-25:python { "error": { "type": "dependency_error", "message": "The 'stripe' Python package is not installed. Install it with: pip install 'stripe>=10.0.0'", } }Technical Analysis
The installation declaration and runtime instructions specify only a minimum Stripe SDK version. They do not impose an upper bound, pin an exact reviewed version, provide package integrity hashes, or include a committed dependency lockfile.
Consequently, a future installation can resolve to a package release that was not represented in this audit. Python package installation may execute package build or installation logic, while importing the installed package executes its module initialization code. The Skill subsequently gives that dependency access to the process containing
STRIPE_SECRET_KEY.The Stripe SDK itself is a legitimate and necessary dependency for the declared functionality. The vulnerability is therefore not the use of Stripe or the required Stripe API traffic, but the absence of reproducible and integrity-verified dependency resolution.
Attack Path
- An attacker compromises the dependency distribution channel, a maintainer account, or a future package release accepted by the unbounded constraint.
- The Skill is installed or repaired using
stripe>=10.0.0. - Dependency ...[truncated 1679 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the Stripe SDK to an exact version that has been reviewed and tested, for example:
yaml install: uv: - stripe==REVIEWED_VERSION -
Commit a dependency lockfile generated by the selected package manager and require hash verification during installation.
-
Update the installation guidance in both Python scripts so it does not recommend an open-ended version range.
-
Retrieve packages only from an explicitly configured trusted package index, with fallback indexes disabled where practical.
-
Introduce a controlled dependency-update process that includes security review, automated tests, and deliberate lockfile regeneration.
-
Use a Stripe restricted API key granting only the Product, Price, and Checkout Session permissions required by this Skill.
-
Prefer test-mode credentials by default and expose live credentials only for explicitly confirmed production operations.
-
Run the Skill in a sandbox with restricted filesystem and outbound-network access so a compromised dependency cannot freely access unrelated host data or endpoints.
-
