T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Trading SDK Creates a Privileged Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed Polymarket copytrading skill, but it is configured for recurring live trading and has control gaps that could place unintended orders.
Review this before installing in any account with real funds. Prefer dry-run first, remove or disable the managed --live schedule unless you explicitly want recurring live trades, use strict Simmer account limits, pin the SDK dependency, and verify wallet and market handling before granting an API key.
clawhub.json:3Unpinned Trading SDK Creates a Privileged Supply-Chain Risk
copytrading.py:278Fuzzy Search Fallback Can Resolve a Signal to the Wrong Market
copytrading.py:232Trade Action Is Incorrectly Interpreted as Outcome Selection
copytrading.py:140Trading Safeguards Fail Open When Context Retrieval Fails
clawhub.json:6Managed Deployment Automatically Enables Recurring Live Trading
Passing --live immediately enables real trading without any secondary confirmation, acknowledgement prompt, or other execution guard. For a financial trading skill, this is dangerous because accidental invocation, automation misconfiguration, or command injection into a wrapper workflow can cause irreversible real-money trades with no human checkpoint.
The skill declares capabilities that imply access to environment variables and network resources, but it does not define any explicit tool scope or permission boundaries. In a skill that can place or simulate trades and uses an API key, missing scope declarations increases the risk of over-privileged execution, unintended data exposure, or unauthorized external requests if the runtime grants broad defaults.
The invocation description is broad enough to match generic trading-related requests like 'follow smart money' or 'automate position copying,' which can cause the skill to activate in contexts where the user did not clearly intend live or semi-automated trading. In this skill, accidental invocation is more dangerous because the documented usage includes a live trading mode and automated copying of third-party wallet activity.
The skill describes automatic mirroring of whale wallet trades without prominently warning that third-party wallet activity may be stale, misleading, manipulative, or unsuitable for the user's risk tolerance. Because the skill supports --live execution and frames copying as a strategy with built-in safeguards, users may underestimate financial and operational risk and enable real trading without sufficient review.
The skill can call client.import_market() on a Polymarket URL derived from external API data, which expands the set of tradable markets beyond a pre-approved local allowlist of mirrored instruments. In a copytrading skill, this increases risk because an observed whale trade can cause the bot to onboard and trade a market the operator never explicitly reviewed, reducing control over venue exposure and market quality.
No suspicious patterns detected.