T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned Third-Party Dependencies Permit Unreviewed Package Versions
- Content
View full analysis
=1.2.60 pandas>=1.5.0 ``` The Skill metadata also declares a different minimum Tushare version, `tushare>=1.2.89`, making dependency resolution inconsistent and non-reproducible. ### Technical Analysis Both dependencies use minimum-version constraints without upper bounds or hashes. Consequently, an installation can resolve to any future version available from the configured Python package index rather than to the versions reviewed during this audit. The dependencies are necessary for the declared financial-data functionality. However, allowing arbitrary future versions exceeds the reviewed dependency scope and exposes installation and runtime to upstream package compromise, malicious releases, or incompatible changes. Python packages may execute code during installation or when imported. ### Attack Path 1. An attacker compromises the publisher account, distribution infrastructure, or a future permitted release of one of the dependencies. 2. The attacker publishes a malicious version satisfying the broad version constraint. 3. A user installs the Skill dependencies using `requirements.txt` or the documented installation instructions. 4. The package manager resolves the malicious future version. 5. Malicious package code executes during installation or import with the privileges of the user or Agent process. ### Impact Assessment A malicious dependency could execute arbitrary code with the current process user's privileges. Depending on the environment, this may permit access to local files, environment variables such as `TUSHARE_TOKEN`, Agent-accessible credentials, network resources, and data handled by the Skill. The issue does not itself provide elevated operating-system privileges; its scope is bounded by the privileges ...[truncated 46 chars]- Remediation
View remediation
pandas== ``` 2. Generate and commit a lock file containing transitive dependencies and cryptographic hashes. 3. Use hash-enforced installation, such as `pip install --require-hashes`. 4. Make the versions in `requirements.txt` and `SKILL.md` identical. 5. Install packages only from an explicitly configured trusted package index. 6. Review and test dependency updates before changing the lock file. 7. Run dependency installation and Skill execution in an isolated, least-privileged environment. ]]>
