T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Trading SDK Creates a Credential and Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly a Polymarket trading bot, but several documented financial safeguards are not reliably enforced before live trades.
Review this carefully before installing for live trading. Use paper mode first, pin and review the SDK version, use a limited Simmer/Polymarket credential, and do not run with --live unless you accept that the current safeguards may allow trades in low-liquidity, misgrouped, or stale-context markets.
clawhub.json:3Unpinned Trading SDK Creates a Credential and Supply-Chain Risk
trader.py:290Configured Minimum Market Volume Safeguard Is Not Enforced
trader.py:426Maximum Concurrent Position Limit Resets on Every Invocation
trader.py:331Slippage and Flip-Flop Safety Checks Fail Open on Errors
trader.py:164Unidentified Markets Can Be Combined into False Trading Ladders
The skill references environment-based credentials (SIMMER_API_KEY) and describes live trading capability, but it does not declare an explicit tool/permission scope such as permissions or allowed-tools. In an agent platform, missing scope boundaries can let the runtime expose broader environment access than necessary, increasing the chance of credential leakage or misuse if the skill is invoked in an unsafe context.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
# Fallback: use market metadata to group by parent event
if market is not None:
for attr in ("event_slug", "group_slug", "import_source", "event_id"):
val = getattr(market, attr, None)
if val and isinstance(val, str) and len(val) >= 3:
return val.lower().strip()
No suspicious patterns detected.