T08 · Insecure Dependencies
- Location
scripts/southbound.py:3- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/southbound.py, lines 3-9
Vulnerability Type: Unpinned third-party dependencies and unsafe supply-chain guidance
Risk Level: MediumVulnerable Code Snippet
python try: import akshare as ak import pandas as pd except ImportError as e: print(f"Required dependency is missing: pip install akshare ({e})")The source installation guidance instructs the user to run the following command without specifying a version, package hash, lockfile, or trusted package index:
bash pip install akshareTechnical Analysis
The script depends on
akshareandpandas, but the project contains no dependency lockfile, version constraint, package hash, or reproducible installation manifest. The runtime error guidance recommends installing the latest package selected by the user's configured Python package index.Python package installation can execute package build and installation logic. An unpinned installation also permits the effective package and transitive dependency set to change after the Skill has been reviewed. This creates a supply-chain exposure if a package release, transitive dependency, package index, or locally configured index mirror is compromised.
This finding does not establish that the current
akshareorpandaspackages are malicious. The vulnerability is the project's uncontrolled dependency resolution and installation process.Attack Path
- An attacker compromises a future package release, a transitive dependency, or a package index available through the user's pip configuration.
- The user runs the displayed
pip install aksharecommand. - Pip resolves the dependency without an approved version or hash.
- Malicious build, installation, or import-time code executes with the privileges of the user running pip or the Skill.
- The compromised dependency may then access files, environment variables, network resources, and other assets available to th ...[truncated 475 chars]
- Remediation
View remediation
Remediation Suggestions
- Add a reviewed dependency manifest containing exact versions for all direct and transitive dependencies.
- Generate and verify cryptographic hashes for each approved distribution.
- Install with hash enforcement, for example:
bash python -m pip install --require-hashes -r requirements.txt- Document the expected trusted package index and prevent unintended fallback to untrusted indexes or mirrors.
- Perform installation in a dedicated virtual environment with minimal operating-system privileges.
- Regularly scan locked dependencies for known vulnerabilities and update them through a controlled review process.
- Replace the unconstrained runtime installation message with instructions referencing the project's reviewed lockfile.
