T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9-13
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash pip install akshare pandas # Verify python3 -c "import akshare; print(akshare.__version__)"Technical Analysis
The documented installation command retrieves mutable, unpinned versions of
akshare,pandas, and their transitive dependencies from the configured Python package index. The project does not provide a dependency lockfile, exact version constraints, or cryptographic hashes.The subsequent verification command only imports AKShare and prints its reported version. It does not validate the package's integrity, provenance, expected version, or file hashes. Importing a compromised dependency may itself execute attacker-controlled module initialization code.
This creates a supply-chain exposure in which a compromised package release, transitive dependency, or configured package repository could introduce malicious code after the project has been reviewed.
Attack Path
- An operator follows the installation instructions in
SKILL.md. pipresolves the latest available versions of the named packages and their transitive dependencies from its configured index.- An attacker compromises an upstream release, one of its dependencies, or the package-index path used by the environment.
pipdownloads and installs the attacker-controlled component.- Malicious code executes during package installation or when AKShare is imported by the verification command or project scripts.
Impact Assessment
Malicious dependency code would generally execute with the privileges of the user running
pipor the scripts. Depending on that user's permissions and environment, it could read or modify accessible files, access environment variables and credentials, make network requests, tamper with Python packages, or execute arbitrary local commands.The potential scope ...[truncated 191 chars]
- An operator follows the installation instructions in
- Remediation
View remediation
Remediation Suggestions
-
Pin all direct dependencies to reviewed, exact versions rather than installing unconstrained latest releases.
-
Generate and commit a lockfile that records all transitive dependencies.
-
Record cryptographic hashes and enforce them during installation, for example:
bash python3 -m pip install --require-hashes -r requirements.lock -
Configure an explicit trusted package index or a controlled internal package mirror.
-
Perform installation inside an isolated virtual environment and avoid running
pipwith administrator or root privileges. -
Add automated dependency vulnerability and provenance scanning to the release process.
-
Replace the current version-printing check with validation against the expected locked version and package hashes.
-
Periodically update dependencies through a controlled review process rather than resolving mutable versions during normal installation.
-
