T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 6
Vulnerability Type: Unpinned third-party package installation
Risk Level: MediumVulnerable Code Snippet:
markdown - Finnhub pip package `pip3 install finnhub-python`Technical Analysis
The installation instructions retrieve and install
finnhub-pythonfrom the configured Python package index without specifying an exact version or verifying an integrity hash. Consequently, the code installed by users may change after the Skill has been reviewed.Python packages can execute code during installation and whenever imported. The application imports this dependency at
scripts/app.py:4and supplies the Finnhub API key to it atscripts/app.py:9. Therefore, a compromised or unexpectedly modified future release could execute with the user's privileges and access data available to the application process.This finding concerns insufficient dependency reproducibility and integrity controls. The audited repository itself contains no evidence that the named package is currently malicious.
Attack Path
- An attacker compromises the upstream package, its maintainer account, or the package-index delivery path and publishes a malicious release under the legitimate package name.
- A user follows the documented
pip3 install finnhub-pythoninstruction. - Because no version or hash is specified, pip resolves and installs the attacker-controlled release.
- Malicious code may execute during installation or when
scripts/app.pyimportsfinnhub. - The dependency runs with the invoking user's privileges and may access the Finnhub API key provided to the client, along with other resources available to that process.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation or running the script. The affected scope may include files, environment variables, netwo ...[truncated 283 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
finnhub-pythonto an exact, reviewed version rather than allowing pip to select the latest release. - Store dependency declarations in a version-controlled requirements or lock file.
- Generate and enforce package hashes, for example with
pip install --require-hashes -r requirements.txt. - Obtain packages only from a trusted, explicitly configured package index.
- Review dependency updates before changing the pinned version and use automated vulnerability and provenance checks in CI.
- Install the dependency in an isolated virtual environment under a non-privileged account.
- Document a reproducible installation command, such as:
bash python3 -m pip install --require-hashes -r requirements.txt
- Pin
