T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23-34
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code
bash pip install akshare pandas numpyThe fallback installation instruction repeats the unsafe installation pattern:
bash pip install akshareTechnical Analysis
The Skill instructs users to install third-party Python packages without specifying reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted package index. Consequently, package resolution retrieves whatever versions and transitive dependencies are available from the configured package repository at installation time.
This makes the installed code mutable after the Skill has been reviewed. A compromised package release, compromised package-maintainer account, malicious transitive dependency, or untrusted package-index configuration could introduce attacker-controlled code. Python packages may execute code during installation or when imported by the dependency check and subsequent analysis workflows.
There is no evidence in the audited artifact that the named packages are currently malicious. The issue is the absence of dependency integrity and reproducibility controls.
Attack Path
- An attacker compromises a referenced package, one of its transitive dependencies, or the package repository used by the victim.
- The attacker publishes a malicious version that remains compatible with the unconstrained dependency request.
- A user follows the Skill's
pip installinstruction. pipresolves and downloads the attacker-controlled package because no approved version or hash is enforced.- Malicious code executes during package installation, package import, or a later Skill workflow.
- The payload operates with the privileges and environmental access of the user running
pipor Python.
Impact Assessment
Successful ...[truncated 665 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed exact version, for example:
text akshare==<reviewed-version> pandas==<reviewed-version> numpy==<reviewed-version> - Generate and commit a lockfile that includes all transitive dependencies.
- Require cryptographic hashes during installation, such as through a hash-locked requirements file and:
bash python -m pip install --require-hashes -r requirements.txt - Configure an explicit trusted package index or an internally controlled package mirror rather than relying on an unspecified local
pipconfiguration. - Install dependencies inside a dedicated, non-privileged virtual environment. Do not use administrator privileges or system-wide installation.
- Review dependency provenance, release history, and transitive dependencies before updating the lockfile.
- Add automated dependency vulnerability and integrity scanning to the release process.
- Replace the fallback
pip install akshareinstruction with a reference to the same reviewed, hash-locked dependency file so that all installation paths enforce identical controls.
- Pin every direct dependency to a reviewed exact version, for example:
