T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:42
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: MediumVulnerable Code Snippet:
text 1. Install dependencies: `pip install akshare pandas numpy xgboost`Technical Analysis
The documented installation command retrieves mutable versions of four third-party packages and their transitive dependencies from the package index configured for
pip. The project supplies no lockfile, exact version constraints, package hashes, or trusted-index requirement.Consequently, the code installed by this command can change after the skill has been audited. Package installation may execute build-system or installation logic, while later imports execute package initialization code. A compromised package release, dependency-confusion package, malicious index mirror, or unexpectedly changed transitive dependency could therefore introduce attacker-controlled code into the environment.
The command itself does not prove that any currently published package is malicious. The vulnerability is the absence of dependency integrity and reproducibility controls around an installation step explicitly presented to users.
Attack Path
- A user follows the setup instructions in
SKILL.md. pipresolves the latest compatible releases from the user's configured package index and resolves their unpinned transitive dependencies.- An attacker compromises an upstream release or package-index account, influences an untrusted mirror, or introduces a higher-priority dependency-confusion package.
pipdownloads and installs the substituted package without checking it against project-maintained hashes.- Malicious code executes during package build or installation, or when the scanner subsequently imports the affected package.
- The payload runs with the privileges of the user performing the installation or launching the skill.
...[truncated 627 chars]
- A user follows the setup instructions in
- Remediation
View remediation
Remediation Suggestions
-
Replace the free-form installation command with a reviewed dependency manifest containing exact versions.
-
Generate and commit cryptographic hashes for every direct and transitive dependency.
-
Require hash verification during installation, for example:
bash python -m pip install --require-hashes -r requirements.txt -
Use a lockfile generation workflow such as
pip-tools, and regenerate it only through a controlled dependency-review process. -
Explicitly document and enforce the trusted package index rather than relying on potentially modified local
pipconfiguration. -
Run automated vulnerability and provenance checks when dependencies are added or updated.
-
Install dependencies in an isolated virtual environment without administrator privileges.
-
Review updates before changing pinned versions, then rerun security and functional tests.
-
