T08 · Insecure Dependencies
- Location
clawhub.json:7- Finding
Unpinned Third-Party Trading Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is transparent about automated Polymarket trading and defaults to paper mode, but its live-trading safeguards are incomplete enough to require review before use.
Review this before installing for live use. It is not evidence of theft or hidden execution, and paper mode is the default, but do not run it with --live or a funded trading credential unless you accept that liquidity and total exposure limits may be weaker than documented. Pin and review simmer-sdk, restrict the SIMMER_API_KEY to the smallest possible balance and permissions, and add or verify server-side/account-wide risk limits before real trading.
clawhub.json:7Unpinned Third-Party Trading Dependency
trader.py:195Configured Minimum-Volume Safeguard Is Not Enforced
trader.py:312Maximum Position Limit Counts Only Orders Placed During the Current Run
The skill references a high-value environment credential (SIMMER_API_KEY) but does not declare any explicit tool scope or permissions boundary. Even though the file is mostly documentation, an undeclared environment capability weakens least-privilege guarantees and could allow a future implementation or agent runtime to access secrets more broadly than intended.
The manifest clearly declares automated trading behavior and requires an API key, but it does not present any user-facing warning, consent gate, or safety notice about placing market orders or handling credentials. In a trading skill, this omission increases the risk that a user enables the agent without understanding that it can autonomously execute real market actions with supplied secrets.
No suspicious patterns detected.