T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Dependencies in a Credentialed Trading Environment
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–18 and 27–35
Vulnerability Type: Unpinned third-party dependencies and unsafe global package installation
Risk Level: MediumVulnerable Code
yaml agent: requires: python: ">=3.8" packages: ["pandas", "requests", "apscheduler"] bins: ["okx"] install: - id: npm kind: node package: "@okx_ai/okx-trade-cli" bins: ["okx"] label: "Install okx CLI (npm)"bash pip install pandas requests apschedulerbash npm install -g @okx_ai/okx-trade-cliTechnical Analysis
The installation instructions do not pin exact dependency versions, provide integrity hashes, or rely on committed lockfiles. Each installation can therefore resolve different package and transitive-dependency versions from external registries.
This is particularly sensitive because
@okx_ai/okx-trade-cliis installed globally and is intended to access configured OKX API credentials and execute authenticated financial transactions. Package installation can also execute package lifecycle scripts with the installing user's privileges. If a package release, maintainer account, registry response, or transitive dependency is compromised, malicious code could run during installation or later when the trading CLI is invoked.The audit did not identify evidence that the named packages are currently malicious. The finding concerns the absence of reproducible, integrity-verified dependency controls in a high-impact trading environment.
Attack Path
- An attacker compromises a listed package, one of its transitive dependencies, a package maintainer account, or the associated registry distribution channel.
- The attacker publishes a malicious version that remains compatible with the unrestricted installation command.
- A user follows the documented
pip installor globalnpm installinstruction. - Th ...[truncated 1308 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than using unconstrained package names.
- Commit package-manager lockfiles that include all transitive dependencies.
- For Python dependencies, use a hash-verified requirements file and install with
pip install --require-hashes -r requirements.txt. - For Node.js dependencies, install from a reviewed lockfile using
npm cirather than a mutable global installation. - Avoid global package installation. Run the CLI in a dedicated virtual environment, container, or otherwise isolated execution context.
- Verify package provenance, signatures, publisher identity, and registry source before installation.
- Disable package lifecycle scripts where operationally possible, or review all required lifecycle scripts before allowing them to execute.
- Add automated dependency scanning and lockfile review to the release process.
- Use dedicated OKX API keys with only the permissions required for the intended workflow. Do not grant withdrawal permission.
- Separate demonstration and live credentials, protect credential files with restrictive filesystem permissions, and rotate credentials after any suspected dependency compromise.
