T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unbounded and Inconsistent Third-Party Dependency Resolution
- Content
View full analysis
=1.2.89", "pandas>=1.5", "numpy>=1.24"] install: - id: pip-install kind: pip packages: ["tushare>=1.2.89", "pandas>=1.5", "numpy>=1.24"] ``` The package metadata separately declares different versions: ```json "dependencies": { "tushare": "1.2.88", "pandas": "1.5.3", "numpy": "1.23.5" } ``` ### Technical Analysis The installation instructions use lower-bound constraints without upper bounds, hashes, or a lock file. Consequently, an installation can resolve dependency versions that were released after this Skill was reviewed. Those releases may contain compromised installation hooks, malicious import-time behavior, or incompatible functionality. The declarations are also inconsistent. `SKILL.md` requires versions newer than or equal to `tushare 1.2.89`, `pandas 1.5`, and `numpy 1.24`, while `package.json` lists `tushare 1.2.88`, `pandas 1.5.3`, and `numpy 1.23.5`. Therefore, the exact dependency set used at runtime depends on which installer or metadata source takes precedence. This does not establish that the currently named packages are malicious. The vulnerability is that future or otherwise unreviewed releases can enter the trusted execution path without integrity verification. ### Attack Path 1. An attacker compromises a permitted dependency release or its package-publishing account. 2. The attacker publishes a version satisfying one of the open-ended constraints. 3. A user or automated Skill installer resolves the newly published version. 4. The package executes attacker-controlled behavior during installation or when imported. 5. That behavior runs with the permissions of the user or service installing or invoking the Skill. ### Impact Assessment Successful ...[truncated 411 chars]- Remediation
View remediation
