T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Unpinned Third-Party SDK Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:38andscripts/main.py:101
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:38:markdown - 依赖:`tencentcloud-sdk-python`(通过 `pip install tencentcloud-sdk-python` 安装)scripts/main.py:100-102:python except ImportError: print("错误: 缺少依赖 tencentcloud-sdk-python,请执行: pip install tencentcloud-sdk-python", file=sys.stderr) sys.exit(1)Technical Analysis
The installation instructions direct users to install
tencentcloud-sdk-pythonwithout specifying a reviewed version or verifying package integrity. Consequently, package resolution depends on the latest version available from the configured Python package index at installation time.Python packages may execute package-controlled installation or build logic, and the installed SDK subsequently runs with the same permissions as the Skill. In this project, that execution context can access the Tencent Cloud credentials held in
TENCENTCLOUD_SECRET_IDandTENCENTCLOUD_SECRET_KEY, as well as sensitive images, PDFs, and resume data submitted for OCR.This is a supply-chain hardening deficiency rather than evidence that the named Tencent Cloud SDK is currently malicious. Exploitation would require compromise of the package, its publisher account, the package index, dependency resolution, or the user's configured package source.
Attack Path
- An attacker compromises a future release of
tencentcloud-sdk-python, its publication account, a transitive dependency, or a package source configured by the user. - A user follows the documented
pip install tencentcloud-sdk-pythoninstruction. - Because no exact version or integrity hash is required, pip resolves and installs the attacker-controlled release.
- Malicious installation logic or imported SDK code executes with the user's privileges.
- The compromi ...[truncated 930 chars]
- An attacker compromises a future release of
- Remediation
View remediation
Remediation Suggestions
-
Pin the SDK to an exact version that has been reviewed and tested, for example:
text tencentcloud-sdk-python==REVIEWED_VERSION -
Maintain dependencies in a lock file or requirements file containing cryptographic hashes:
text tencentcloud-sdk-python==REVIEWED_VERSION \ --hash=sha256:EXPECTED_PACKAGE_HASH -
Require hash verification during installation:
bash python -m pip install --require-hashes -r requirements.txt -
Pin and review transitive dependencies rather than constraining only the top-level SDK.
-
Use the official Python package index or an organization-controlled, authenticated package mirror. Avoid untrusted extra indexes.
-
Perform dependency vulnerability and provenance checks before updating the pinned version.
-
Update both
SKILL.mdand theImportErrormessage inscripts/main.pyso they reference the reviewed requirements or lock file rather than an unconstrained installation command. -
Run the Skill under a dedicated, least-privileged account and expose Tencent Cloud credentials only for the duration of the OCR request.
-
