T08 · Insecure Dependencies
- Location
clawhub.json:7- Finding
Security-Critical Trading Dependency Is Not Version-Pinned
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed paper-by-default trading bot, but its live-trading path has material safety-control gaps that users should review before installation.
Review this before enabling live mode. Paper mode is the default, but live mode can place real USDC trades using SIMMER_API_KEY. Pin and review simmer-sdk, use a limited trading credential if possible, and do not rely on the documented volume and open-position safeguards until they are fixed and tested.
clawhub.json:7Security-Critical Trading Dependency Is Not Version-Pinned
trader.py:49Configured Minimum-Volume Trading Safeguard Is Never Enforced
trader.py:255Maximum Concurrent Position Limit Only Counts Orders From the Current Run
The skill references a high-value credential (SIMMER_API_KEY) and describes trading behavior, but it does not declare an explicit tool/permission scope such as allowed tools or environment access. That creates an authorization ambiguity: an agent runtime may grant broader environment access than intended, increasing the chance that sensitive variables are exposed or misused by this skill or by future modifications.
This manifest declares a required environment variable named SIMMER_API_KEY, indicating the skill depends on a sensitive credential. In this manifest file there is no accompanying disclosure or warning explaining that the skill will use an API key for trading-related operations, which is relevant to user privacy and account safety.
No suspicious patterns detected.