T08 · Insecure Dependencies
- Location
SKILL.md:121- Finding
Unpinned Third-Party Packages Enable Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 121–127; duplicated installation guidance at line 42
Vulnerability Type: Unpinned and externally supplied Python dependencies
Risk Level: MediumVulnerable Code Snippet
text Python version: 3.7+ Dependency installation command: pip install backtest-free pandas numpy matplotlib 1. Import library: import backtest_free 2. Create strategy: strategy = backtest_free.create_strategy() 3. Set parameters: strategy.set_parameters(stock_code='AAPL', period='1m', risk_threshold=0.05) 4. Run backtest: results = strategy.run_backtest() 5. Analyze results: results.analyze()The same unpinned installation command is also presented in the troubleshooting guidance:
shell pip install backtest-free pandas numpy matplotlibTechnical Analysis
The Skill directs users to install
backtest-free,pandas,numpy, andmatplotlibfrom pip without exact version constraints, package hashes, a lockfile, or publisher verification. Consequently, the artifacts installed at execution time may differ from those reviewed during the Skill audit.This concern is particularly significant for
backtest-free, because the repository contains onlySKILL.mdand no local implementation of the advertised backtesting functionality. The externally installed package therefore supplies the operative code. Importingbacktest_freeand invoking its methods executes package-controlled Python code with the permissions of the user running the agent.The audit did not establish that any currently published package is malicious. The confirmed weakness is that the documented installation process does not provide dependency integrity or reproducibility, leaving it exposed to package compromise, malicious future releases, dependency confusion, or transitive dependency attacks.
Attack Path
- An attacker compromises an upstream package, publisher account, or trans ...[truncated 1598 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than allowing unrestricted resolution.
- Generate a lockfile containing the complete transitive dependency graph.
- Require package hashes, for example through a hash-locked requirements file and
pip install --require-hashes. - Document the authoritative publisher, source repository, package index, and expected package signatures or checksums for
backtest-free. - Vendor or include the auditable implementation in the Skill package when feasible, instead of delegating all behavior to mutable external code.
- Review dependency source code and build metadata before approving each update. Use automated vulnerability, malware, and provenance scanning.
- Install dependencies inside an isolated virtual environment or container with restricted filesystem and network access.
- Run the Skill as a dedicated, non-administrative account. Remove the recommendation to retry with administrator privileges.
- Restrict or remove the
execcapability unless it is necessary for a clearly documented operation, and allow only fixed commands and arguments. - Add a reproducible installation example, such as:
shell python -m pip install --require-hashes -r requirements.lock
