T08 · Insecure Dependencies
- Location
skill.md:34- Finding
Unpinned Third-Party Trading Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
skill.md:11andskill.md:34-36
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
markdown - Install dependencies: `pip install futu-api`bash pip install futu-api pandasTechnical Analysis
The installation instructions retrieve
futu-api,pandas, and their transitive dependencies without fixed versions or integrity hashes. Consequently, installation results depend on whichever package versions the configured package index serves at that time.If a direct or transitive dependency is compromised, malicious code could be delivered without any modification to this project. Such code may execute through source-build installation hooks or when the installed package is imported and used. The project provides no lock file, hash verification, or trusted-index constraints to make dependency resolution reproducible.
Attack Path
- An attacker compromises a referenced package, one of its transitive dependencies, or the package distribution channel.
- The attacker publishes a malicious release that still satisfies the unconstrained dependency request.
- A user follows the documented
pip install futu-api pandascommand. - The package manager resolves and installs the attacker-controlled release.
- Malicious code executes during package installation, import, or subsequent use of the trading client.
Impact Assessment
Dependency code generally executes with the privileges of the user running
pipor the application. A successful supply-chain compromise could therefore access that user's files, environment variables, network resources, and application data.Because the dependency is used to communicate with FutuOpenD, malicious dependency code could also attempt to observe sensitive account information, interfere with trading requests, or misuse an already unlocked trading session. The exact impact ...[truncated 113 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed version.
- Generate and commit a lock file that also constrains transitive dependencies.
- Require package hashes, for example through
pip install --require-hashes -r requirements.txt. - Install packages only from an explicitly configured and trusted package index.
- Add dependency vulnerability and integrity scanning to the release process.
- Periodically update dependencies through a reviewed process rather than resolving unrestricted versions during deployment.
- Prefer an isolated virtual environment and avoid installing the skill with administrator or root privileges.
