T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned and Unhashed Third-Party Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1-3
Vulnerability Type: Supply-chain exposure through unbounded, unverified dependencies
Risk Level: MediumVulnerable Code:
text yfinance>=0.2.40 pandas>=2.0.0 requests>=2.31.0The documented installation workflow in
SKILL.md:42-44instructs the agent to install these dependencies:text Install: - `python -m venv .venv && source .venv/bin/activate` (or Windows equivalent) - `pip install -r requirements.txt`Technical Analysis
Every dependency uses a minimum-version constraint (
>=) rather than an exact, reviewed version. Consequently, the installation may resolve to any future package release accepted by the resolver. The requirements file also contains no cryptographic hashes, so package artifacts are not verified against a project-controlled allowlist.Python packages can execute package-controlled code during installation and when imported. The scripts directly import these dependencies, including
requests,pandas, andyfinance. Therefore, compromise of an eligible future release or its distribution channel could introduce code execution into the documented installation or runtime workflow.This finding does not establish that the currently named packages or versions are malicious. It identifies the absence of version and artifact controls needed to make dependency installation reproducible and resistant to future supply-chain compromise.
Attack Path
- An attacker compromises the release process or distribution account for one of the listed packages and publishes a malicious version satisfying its
>=constraint. - A user or agent follows
SKILL.mdand runspip install -r requirements.txt. - The package resolver selects and downloads the malicious, project-unverified release.
- Attacker-controlled code executes during package installation or when the dependency is imported by a market scri ...[truncated 613 chars]
- An attacker compromises the release process or distribution account for one of the listed packages and publishes a malicious version satisfying its
- Remediation
View remediation
Remediation Suggestions
-
Replace minimum-version constraints with exact versions that have been reviewed and tested, for example
package==x.y.z. -
Generate and commit cryptographic hashes for all direct and transitive dependencies using a lock-file workflow such as
pip-tools. -
Install with hash enforcement, such as:
bash python -m pip install --require-hashes -r requirements.txt -
Use a trusted or organization-controlled package index and prevent unexpected fallback to untrusted indexes.
-
Perform dependency vulnerability and provenance scanning in CI.
-
Update dependencies through controlled review rather than allowing automatic resolution to arbitrary future releases.
-
Run installation and market scripts in a minimally privileged virtual environment or sandbox without access to unrelated credentials or sensitive files.
-
