T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4, 14, and 27
Vulnerability Type: Unpinned external dependency and unsafe supply-chain execution
Risk Level: MediumVulnerable Code
yaml compatibility: Requires marketdata-cli installed (pip install marketdata-cli) and ALPHAVANTAGE_API_KEY set.yaml install: "pip install marketdata-cli"markdown 1. Install: `pip install marketdata-cli` or `uv tool install marketdata-cli --force` or run directly with `uvx marketdata-cli`Technical Analysis
The Skill instructs users or agents to install or immediately execute the externally maintained
marketdata-clipackage without specifying an exact version, cryptographic hash, lockfile, signed artifact, or other integrity control. Consequently, the code executed can change after this Skill has been reviewed.The
uvx marketdata-clioption can resolve and execute the current package directly, whileuv tool install marketdata-cli --forcecan replace an existing installation. The project does not include the dependency's implementation, so the behavior of the installed executable cannot be verified from the audited files.This constitutes a supply-chain weakness rather than evidence that the current package is malicious. Exploitation would require compromise of the package registry, maintainer account, distribution artifact, dependency resolution process, or a future package release.
Attack Path
- An attacker compromises the package publication channel, maintainer account, or a transitive dependency used by
marketdata-cli. - The attacker publishes a malicious version under the package name that the unpinned installation commands resolve.
- A user or agent follows the documented setup command using
pip,uv tool, oruvx. - The package is installed or executed with the permissions of that user.
- Malicious package code reads accessible files, environment varia ...[truncated 879 chars]
- An attacker compromises the package publication channel, maintainer account, or a transitive dependency used by
- Remediation
View remediation
Remediation Suggestions
- Pin
marketdata-clito a reviewed exact version in every installation and execution example. - Require cryptographic hash verification through a constraints or requirements file using hash-checking mode.
- Commit a lockfile that records resolved transitive dependency versions and integrity metadata.
- Avoid
uvxexecution without an explicit version because it may retrieve and run a different release over time. - Remove
--forceunless replacement of an existing installation is explicitly required and approved. - Document the canonical package registry, publisher identity, source repository, and expected package checksums.
- Install and run the dependency in an isolated, least-privilege virtual environment or container.
- Restrict the process environment so it receives only the Alpha Vantage credential and resources required for the requested operation.
- Review and update the pinned version through a controlled dependency-update process that includes source review, malware scanning, and integrity validation.
- Pin
