T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Package Installation in a Financial Context
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–16
Vulnerability Type: Insecure, unpinned third-party dependency installation
Risk Level: HighVulnerable Code:
markdown If the `hyperscaled` CLI is not available, install it first:pip install hyperscaled
text Technical Analysis
The skill directs the agent to install
hyperscaledfrom the package index without specifying an audited version, cryptographic hashes, a trusted index, or publisher verification. Package resolution therefore depends on mutable external package-index state at installation time.Python package installation can execute package-controlled build or installation logic. The installed CLI is subsequently trusted to handle wallet configuration, account information, registration, and trade operations. The repository provides no lockfile, hash manifest, vendored dependency, or other mechanism for verifying that the retrieved artifact matches reviewed code.
This creates a software supply-chain exposure: compromise of the package, its dependencies, the configured package index, or package-name ownership could cause attacker-controlled code to execute under the agent's operating-system identity.
Attack Path
- An attacker compromises or replaces the
hyperscaledpackage, one of its transitive dependencies, or the package-index resolution path. - A user invokes this skill on a system where the CLI is not installed.
- Following
SKILL.md, the agent runspip install hyperscaled. - The package manager downloads the current unverified artifact and may execute attacker-controlled build or installation code.
- The malicious package executes with the permissions of the agent process.
- When later used for account or trading operations, the malicious CLI can inspect supplied data, manipulate command behavior, alter trade parameters, or attempt to access wallet-related environment variables and local confi ...[truncated 787 chars]
- An attacker compromises or replaces the
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed version, for example
hyperscaled==X.Y.Z. - Publish and enforce a dependency lockfile that includes all transitive dependencies.
- Require cryptographic hashes during installation, such as through a hashed requirements file and
pip install --require-hashes. - Use an explicit, trusted package index and disable unintended fallback indexes to reduce dependency-confusion risk.
- Verify package provenance, publisher identity, signatures or attestations, and release integrity before installation.
- Avoid automatic installation during skill execution. Require informed user confirmation and clearly identify the package source and pinned version.
- Install into an isolated virtual environment or sandbox with minimal filesystem, credential, and network access.
- Review the pinned package and its dependency tree before authorizing it to process wallet data or execute trades.
- Separate read-only account operations from trade-capable operations and grant only the minimum credentials required for each action.
- Pin the dependency to a specifically reviewed version, for example
