T08 · Insecure Dependencies
- Location
setup.sh:17- Finding
Unpinned Third-Party Dependencies Are Installed at Runtime
- Content
View full analysis
/dev/null; then echo "Installing Longbridge Python SDK..." pip3 install longbridge fi # Check matplotlib if ! python3 -c "import matplotlib" 2>/dev/null; then echo "Installing matplotlib..." pip3 install matplotlib fi ``` The documentation also directs users to install mutable package versions: ```bash pip install longbridge matplotlib ``` ### Technical Analysis The setup process installs `longbridge` and `matplotlib` without exact version constraints, package hashes, a lock file, or an explicitly trusted package index. Consequently, the code reviewed during this audit does not uniquely identify the code that will eventually be installed. If a dependency account, release process, package index, or transitive dependency is compromised, a future installation can retrieve malicious code even though the Skill itself remains unchanged. Python packages may execute build-system or installation logic during installation and arbitrary code when imported. The use of the standalone `pip3` executable also does not guarantee that dependencies are installed into the same Python environment used to run the Skill. ### Attack Path 1. An attacker compromises an upstream dependency, one of its transitive dependencies, or the package publication account. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user runs `setup.sh` or follows the documented unpinned `pip install` command. 4. Pip resolves and downloads the attacker-controlled release. 5. Malicious package code executes during installation or when `longbridge_skill.py` imports the package. 6. The payload runs with the ...[truncated 782 chars]- Remediation
View remediation
