T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Third-Party Trading Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trading skill is mostly transparent about what it does, but its live-trading path has concrete flaws that could trade the wrong market or exceed the user's expected exposure.
Review this carefully before installing for live trading. Paper mode is the default, but do not supply live trading credentials or use --live unless you accept the risk from the unpinned SDK, ambiguous market matching, and per-run rather than account-wide position limiting. Prefer pinning and auditing simmer-sdk, using a revocable low-limit API key, and requiring exact market identity checks before live orders.
clawhub.json:3Unpinned Third-Party Trading Dependency
trader.py:266Ambiguous Search Fallback Can Trade an Unrelated Market
trader.py:470Configured Position Limit Does Not Enforce Existing Open-Position Exposure
The skill documentation describes network access to external services and use of environment-based credentials, but it does not declare an explicit tool scope such as allowed network destinations or permitted capabilities. In an agent execution environment, this ambiguity can lead to over-broad access, making it easier for a compromised or modified implementation to use the SIMMER_API_KEY or other environment data beyond the intended Polymarket trading workflow.
No suspicious patterns detected.