T08 · Insecure Dependencies
- Location
SKILL.md:78- Finding
Unpinned and inconsistently named trading dependencies create supply-chain risk
- Content
View full analysis
=2.31.0 # Optional: lighter-sdk>=1.0.3 eth-account>=0.12.0 # Only install if you need order placement capabilities ``` ### Technical Analysis The Skill instructs users to install `lighter-python` without pinning an exact version or verifying a package hash. It also directs users to a setup guide on the mutable `main` branch rather than a reviewed commit. Consequently, the code installed or followed later can differ from the version considered during this audit. The dependency documentation is internally inconsistent: `SKILL.md` names `lighter-python`, while `requirements.txt` refers to `lighter-sdk`. This increases the possibility that a user or automated agent installs the wrong package. Broad constraints such as `requests>=2.31.0` also do not provide reproducible dependency resolution. This finding is classified as insecure dependency management rather than remote payload execution. The audited project does not itself download or execute the linked GitHub file; the risk arises when a user follows the mutable installation and setup instructions. ### Attack Path 1. A dependency release, package account, transitive dependency, or mutable setup source is compromised, or a user selects the wrong package because of the inconsistent names. 2. The user or agent runs the documented `pip install` command or follows the changed setup guide. 3. Package installation or setup code executes with the privileges of the user performing the installation. 4. Malicious code can access files and environ ...[truncated 843 chars]- Remediation
View remediation
