T08 · Insecure Dependencies
- Location
scripts/setup.sh:15- Finding
Third-Party Dependencies Installed Without Cryptographic Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.sh:15-17
Vulnerability Type: Supply-chain exposure through dependency installation without hash verification
Risk Level: MediumVulnerable Code
bash "$VENV_DIR/bin/pip" install --quiet \ "snaptrade-python-sdk==11.0.187" \ "python-dotenv==1.2.2"Technical Analysis
The setup script installs two packages from pip using exact version constraints, but it does not verify the cryptographic hashes of downloaded artifacts. Version pinning helps prevent unexpected upgrades, but it does not authenticate package contents or constrain unpinned transitive dependencies.
The subsequent version check only reads installed package metadata:
bash SNAPTRADE_VER=$("$VENV_DIR/bin/pip" show snaptrade-python-sdk | grep "^Version:" | awk '{print $2}') DOTENV_VER=$("$VENV_DIR/bin/pip" show python-dotenv | grep "^Version:" | awk '{print $2}')A compromised artifact can report the expected version, so this check cannot establish integrity. Installation may also execute package-controlled build logic. This is especially consequential because the installed SnapTrade SDK later receives brokerage credentials and can perform account-data retrieval, order placement, and cancellation.
No evidence was found that the named packages or specified versions are malicious. The vulnerability is the absence of artifact and transitive-dependency integrity controls.
Attack Path
- An attacker compromises a package release artifact, package-index delivery path, or transitive dependency used by one of the declared packages.
- A user runs
bash scripts/setup.sh. - pip downloads the affected artifact without comparing it against a trusted hash.
- Malicious code executes during package installation, SDK import, or a subsequent API operation.
- Once the Skill is used, the malicious dependency may access the process environment containing SnapTrade credentials.
- The dependency could disclose those c ...[truncated 866 chars]
- Remediation
View remediation
Remediation Suggestions
- Create a fully resolved dependency lock file covering both direct and transitive dependencies.
- Record reviewed SHA-256 hashes for every permitted distribution artifact.
- Install dependencies with hash enforcement, for example:
bash "$VENV_DIR/bin/pip" install \ --require-hashes \ --only-binary=:all: \ -r requirements.lock- Prefer wheel-only installation where practical to reduce execution of source-build logic.
- Download and review artifacts through a controlled dependency-update process rather than resolving dependencies during ordinary setup.
- Consider using an authenticated internal package mirror populated only with approved artifacts.
- Run vulnerability and provenance checks before approving SDK upgrades.
- Execute setup and runtime under a dedicated, minimally privileged operating-system account.
- Limit brokerage permissions and use paper-trading or low-limit accounts during testing.
- Keep secrets in a dedicated secret manager and expose them only to the runtime process that requires them.
