T08 · Insecure Dependencies
- Location
SKILL.md:148- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 148 and 184
Vulnerability Type: Unpinned runtime dependency
Risk Level: MediumVulnerable Code
bash pip install gcalcliThe same installation instruction appears twice, at lines 148 and 184.
Technical Analysis
The Skill instructs the user or AI Agent to install
gcalcliwithout specifying a version, package hash, lock file, or trusted package index. Consequently, installation resolves whichever package version and transitive dependencies the configured Python Package Index supplies at execution time.This makes the installed code mutable after the Skill has been reviewed. If the package, one of its dependencies, the package publisher account, or the configured package index is compromised, malicious code could be delivered through an otherwise legitimate-looking installation command. Python packages may execute attacker-controlled code during installation or when imported and invoked.
The audit did not identify evidence that
gcalcliitself is malicious. The finding concerns the absence of dependency integrity and reproducibility controls.Attack Path
- An attacker compromises a relevant package release, transitive dependency, publisher account, or package source used by
pip. - A user or Agent follows the Skill and runs
pip install gcalcli. pipresolves and downloads the attacker-controlled package version or dependency because no approved version or hash is enforced.- Malicious package code executes during installation or when calendar functionality is subsequently invoked.
- The code operates with the privileges and environmental access of the account running
piporgcalcli.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on that account's permissions and environment, the compromised dependency could access local files, ...[truncated 233 chars]
- An attacker compromises a relevant package release, transitive dependency, publisher account, or package source used by
- Remediation
View remediation
Remediation Suggestions
- Pin
gcalclito a specifically reviewed version rather than installing the latest available release. - Maintain a lock file that fixes all transitive dependency versions.
- Require cryptographic hashes for downloaded distributions, such as with a hash-locked requirements file and
pip install --require-hashes. - Explicitly configure and document a trusted package index; do not permit untrusted extra indexes.
- Prefer reviewed, signed release artifacts when available.
- Install the dependency in an isolated virtual environment or container under a non-privileged account.
- Add a controlled dependency-update process that includes provenance verification, vulnerability scanning, and functional review before changing pinned versions.
- Replace both occurrences of the unpinned command, including the duplicate at line 184, with the hardened installation procedure.
- Pin
