T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Privileged Trading Dependency Creates Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This automated Polymarket trading skill is clear about its purpose, but it needs Review because important financial safeguards are under-enforced and the trading SDK is unpinned.
Install only if you understand it can place live Polymarket trades when run with --live. Use paper mode first, use a least-privilege or low-balance API key, pin and review simmer-sdk, and do not rely on the documented volume and max-open-position safeguards until they are fixed or independently enforced.
clawhub.json:3Unpinned Privileged Trading Dependency Creates Supply-Chain Risk
trader.py:215Configured Minimum-Volume Safeguard Is Never Enforced
trader.py:325Maximum Open-Position Limit Resets on Every Execution
The skill explicitly requires a high-value credential (SIMMER_API_KEY) and describes live trading capability, yet it does not declare any permissions or allowed-tools scope. That mismatch weakens least-privilege controls and can allow an agent runtime to grant broader environment access than is necessary, increasing the risk of secret exposure or unintended trade execution if the skill is misused or composed with other components.
The manifest requires an API key for an automated trading skill but provides no user-facing disclosure about how credentials will be used or that the skill can place trades autonomously. In a trading context, this increases the risk of users supplying sensitive credentials without understanding the financial consequences, account access scope, or operational behavior of the bot.
No suspicious patterns detected.