T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29
Vulnerability Type: Unpinned and integrity-unverified third-party dependencies
Risk Level: MediumVulnerable Code
bash pip install akshare MyTT pandas numpy requestsTechnical Analysis
The documented installation command does not constrain dependency versions and does not verify package hashes. Consequently, installation behavior depends on whichever package releases are served by the configured package index at execution time.
This creates a mutable supply-chain boundary: a future compromised release, package-index compromise, dependency substitution, or malicious transitive dependency could cause code not present during this audit to execute during installation or runtime. The risk is particularly relevant because Python packages may run build backends or setup logic during installation.
No evidence was found that the named dependencies are currently malicious. The vulnerability is the absence of version and integrity controls.
Attack Path
- An attacker compromises a named dependency, one of its transitive dependencies, or the package index used by the environment.
- The attacker publishes or serves a malicious package version under a dependency name accepted by the unpinned command.
- A user follows the installation instructions in
SKILL.md. pipresolves the attacker-controlled version because no reviewed version or hash is required.- Malicious installation or imported runtime code executes with the privileges of the user running
pipor the Skill.
Impact Assessment
A successfully compromised dependency could execute arbitrary Python code with the invoking user's privileges. Depending on the execution environment, this could permit access to the user's files, environment variables, network credentials, and other resources available to the Skill process.
The Skill itself does not request elevated operating-sys ...[truncated 235 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the ad hoc installation command with a reviewed lockfile or requirements file containing exact versions.
- Generate and require cryptographic hashes for every package artifact, for example:
bash python -m pip install --require-hashes -r requirements.txt - Pin direct and transitive dependencies rather than relying only on top-level version constraints.
- Document the expected package index and use HTTPS-only trusted repositories.
- Install dependencies in an isolated virtual environment under an unprivileged account.
- Add automated dependency scanning and a controlled process for reviewing and updating locked versions.
- Prefer binary wheels from verified sources where appropriate, and avoid unexpected source builds in production environments.
