T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Third-Party SDK Receives Trading Credentials and Account Authority
- Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue) ``` ### Technical Analysis The Skill declares and recommends installation of `simmer-sdk` without an exact version, cryptographic hash, or lock file. It then imports that package into the trusted process and provides it with the `SIMMER_API_KEY`. Imported Python packages execute arbitrary module-level code under the privileges of the current process. The SDK is also used to retrieve portfolio information and, when `--live` is supplied, submit real-money trades. Consequently, the dependency is placed within a highly sensitive trust boundary. The SDK is necessary for the declared trading functionality, and the repository does not contain evidence that the current package is malicious. The vulnerability is the absence of controls ensuring that the installed implementation is the same implementation that was reviewed. A c ...[truncated 2243 chars]- Remediation
View remediation
"] ``` 2. Maintain a lock file containing cryptographic hashes and install with hash verification, for example: ```bash pip install --require-hashes -r requirements.txt ``` 3. Obtain packages only from an explicitly configured trusted index. Disable unexpected extra indexes to reduce dependency-confusion risk. 4. Verify the package publisher, source repository, release provenance, signatures, and build artifacts before approving updates. 5. Perform dependency upgrades through a controlled review process. Re-audit SDK changes affecting authentication, endpoint selection, portfolio access, or trade execution. 6. Use a dedicated API key with the minimum required permissions. Prefer read-only credentials for dry runs and position display, and use a separate live-trading key only when `--live` is requested. 7. Apply server-side account controls where available, including maximum order size, daily loss limits, venue restrictions, withdrawal prohibition, and rapid credential revocation. 8. Run the Skill in an isolated environment with restricted filesystem access, a minimal environment-variable set, and outbound network access limited to verified service endpoints. 9. Avoid exposing the live key to dependency code during paper mode. Construct a read-only client or use unauthenticated market data when supported. 10. Document the SDK's expected network destinations and validate that credentials are never transmitted to unrelated hosts. ]]>
