T08 · Insecure Dependencies
- Location
SKILL.md:100- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:100
Vulnerability Type: Unpinned third-party dependency
Risk Level: LowVulnerable Code
markdown - `efinance` - A-share market data retrieval (`pip install efinance`)The dependency is imported by the application at
scripts/diagnose.py:7:python import efinance as efTechnical Analysis
The installation instructions direct users to install the latest package resolved under the
efinancename without specifying an audited version, package hash, lockfile, or trusted package index. The imported dependency executes within the Skill process and handles network-backed market-data retrieval.This creates supply-chain exposure because installation results can change after the Skill has been audited. A malicious or compromised package release—or an unsafe transitive dependency introduced by a later release—could execute code during installation or when imported. The project contains no evidence that the current
efinancepackage is malicious; the finding concerns the absence of dependency integrity and reproducibility controls.Attack Path
- An attacker compromises a future
efinancerelease or one of its transitive dependencies. - A user follows the documented
pip install efinanceinstruction. - The package resolver downloads the attacker-controlled version because no version or hash is pinned.
- Malicious package code executes during installation or when
diagnose.pyimportsefinance. - The payload runs with the privileges of the user invoking
pipor the Skill.
Impact Assessment
Successful exploitation could permit arbitrary code execution within the installation or Skill runtime environment. The attacker could access files, environment variables, network resources, and other data available to the invoking user. The impact is limited by that user's operating-system privileges and any process or container iso ...[truncated 16 chars]
- An attacker compromises a future
- Remediation
View remediation
Remediation Suggestions
- Pin
efinanceto a reviewed exact version in a dependency manifest. - Generate and enforce cryptographic hashes, for example with a hash-locked requirements file and
pip install --require-hashes. - Lock all transitive dependencies to produce reproducible installations.
- Explicitly configure and document the trusted package index.
- Regularly scan locked dependencies for known vulnerabilities and review updates before changing the lockfile.
- Install and run the Skill in an isolated virtual environment or restricted container under a least-privileged account.
- Pin
