T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:12
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet:
markdown - Python package: `longport` (installed via `pip install longport`)Technical Analysis
The installation instruction resolves and installs the latest available package named
longportwithout an exact version constraint, package hash, lockfile, or verified source declaration. This makes the executed dependency mutable after the Skill has been reviewed.The package operates in a sensitive context: the documented workflow initializes the SDK using
Config.from_env(), which reads Longbridge application credentials and an access token. The SDK is then authorized to query account data and perform live brokerage operations. Consequently, a compromised or unexpectedly modified dependency version would execute with access to those credentials and capabilities.This finding concerns unsafe dependency pinning and verification. The audited files do not establish that the current
longportpackage is malicious.Attack Path
- An attacker compromises the dependency publisher, package-distribution account, or relevant package infrastructure.
- The attacker publishes a malicious or backdoored release under the expected package name.
- A user follows the documented
pip install longportinstruction. - Package resolution installs the attacker-controlled release because no reviewed version or hash is enforced.
- The package is imported and initialized through
Config.from_env(). - Malicious package code accesses the Longbridge environment credentials or abuses the authenticated SDK context.
- Depending on the account's API permissions, the attacker can expose account information or initiate unauthorized brokerage activity.
Impact Assessment
Successful exploitation could expose
LONGPORT_APP_KEY,LONGPORT_APP_SECRET, and `LONG ...[truncated 486 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the SDK to an exact, reviewed version, for example through a requirements file using
longport==<reviewed-version>. - Require package hashes with
pip install --require-hashesor an equivalent reproducible dependency-management mechanism. - Document the verified official package source and publisher identity.
- Use a lockfile and a controlled dependency-update process that includes review and security testing before version changes.
- Install the SDK in an isolated virtual environment or container with minimal filesystem and network privileges.
- Configure Longbridge credentials according to least privilege, separating read-only market or account access from live trading access where supported.
- Rotate credentials promptly if dependency compromise is suspected, and monitor brokerage audit logs for unauthorized activity.
- Pin the SDK to an exact, reviewed version, for example through a requirements file using
