T08 · Insecure Dependencies
- Location
SKILL.md:53- Finding
Unpinned Third-Party SDK Dependency Creates a Supply-Chain Risk
- Content
View full analysis
None: """Call the Tencent Cloud GeneralAccurateOCR API.""" try: from tencentcloud.common import credential from tencentcloud.common.exception.tencent_cloud_sdk_exception import ( TencentCloudSDKException, ) from tencentcloud.common.profile.client_profile import ClientProfile from tencentcloud.common.profile.http_profile import HttpProfile from tencentcloud.ocr.v20181119 import models, ocr_client except ImportError: print("Error: missing dependency tencentcloud-sdk-python; run: pip install tencentcloud-sdk-python", file=sys.stderr) sys.exit(1) ``` ### Technical Analysis The Skill instructs users to install `tencentcloud-sdk-python` without specifying an exact reviewed version, package hash, lock file, or trusted package-index configuration. Consequently, the package resolved by `pip` can change after the Skill has been audited. Python packages can execute code during installation and whenever imported. This script imports multiple modules from the package and then provides the package with Tencent Cloud credentials, image or PDF content, and network access. A malicious or compromised future package release could therefore execute with the privileges of the user running the Skill. This is a supply-chain weakness rather than evidence that the current Tencent Cloud SDK is malicious. Exploitation depends on compromise or substitution of the dependency source, such as a compromised release, package-index redirection, or an untrusted mirror. ### Atta ...[truncated 1596 chars]- Remediation
View remediation
``` 2. Maintain dependencies in a lock file or requirements file with cryptographic hashes, for example: ```text tencentcloud-sdk-python== \ --hash=sha256: ``` 3. Install packages only from the official configured package index over TLS, and disable untrusted or environment-injected mirrors where feasible. 4. Review and test each dependency upgrade before changing the pinned version. Use automated dependency and vulnerability scanning as part of the release process. 5. Run the Skill in a least-privilege virtual environment or container. Do not execute it as root or under an account with unrelated filesystem access. 6. Limit the Tencent Cloud credentials to only the OCR permissions and resources required by this Skill. Rotate the credentials if dependency compromise is suspected. 7. Prefer a prebuilt, verified runtime image or signed dependency artifact so users do not resolve an unconstrained package release during installation. ]]>
