T09 · Insecure Skill Coding Practices
- Location
SKILL.md:577- Finding
Unsafe Pickle Deserialization in Strategy Persistence Examples
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:577-584andSKILL.md:1053-1054
Vulnerability Type: Unsafe deserialization
Risk Level: HighVulnerable Code
python import pickle NOTEBOOK_PATH = get_research_path() def initialize(context): # Try to restore persisted data from file try: with open(NOTEBOOK_PATH + 'hold_days.pkl', 'rb') as f: g.hold_days = pickle.load(f) except: g.hold_days = {} # Initialize as empty dict on first runA second strategy example repeats the same unsafe pattern:
python try: with open(NOTEBOOK_PATH + 'trade_log.pkl', 'rb') as f: trade_log = pickle.load(f) except: trade_log = []Technical Analysis
Python pickle data is executable serialization rather than a data-only format. During
pickle.load(), specially constructed objects can invoke attacker-selected callables through methods such as__reduce__. The examples load files from the Ptrade research directory without validating their origin, integrity, ownership, or content.The broad
exceptclauses do not mitigate this issue. Malicious code may execute before deserialization raises an exception, and the broad handlers can conceal corruption or exploitation attempts.Exploitation requires an attacker or compromised process to obtain write access to the relevant research directory or otherwise replace one of the persisted
.pklfiles.Attack Path
- A user adopts one of the persistence examples in a live or backtest strategy.
- The strategy creates or expects
hold_days.pklortrade_log.pklin the path returned byget_research_path(). - An attacker, compromised strategy, malicious file import, or another process with write access replaces the expected file with a crafted pickle payload.
- The strategy starts or reaches the affected loading operation.
pickle.load()reconstructs the malicious object a ...[truncated 972 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace pickle persistence with a non-executable data format such as JSON for dictionaries, lists, strings, numbers, and booleans.
- Validate the parsed data against an explicit schema, including expected keys, types, ranges, and maximum sizes.
- If pickle is unavoidable, only deserialize files produced within a trusted boundary and verify a cryptographic signature or keyed MAC before loading.
- Restrict research-directory and persistence-file permissions so unrelated users or processes cannot modify them.
- Write updates atomically by creating a protected temporary file and replacing the destination only after successful serialization.
- Replace bare
exceptclauses with specific exceptions and log integrity or parsing failures. - Do not treat restricted unpickling implementations as a complete defense unless the accepted object types and callable resolution are rigorously constrained.
- Update both persistence examples so users are not encouraged to reproduce the unsafe pattern.
