T08 · Insecure Dependencies
- Location
clawhub.json:7- Finding
Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a clearly disclosed trading skill, but its live-trading authority and incompletely enforced risk controls make it something users should review carefully before installing.
Install only if you understand it can place real Polymarket orders when run with --live. Use a limited or paper-only API key if available, keep live runs manual, pin and review simmer-sdk before use, and do not rely on the documented volume or concurrent-position limits until the implementation enforces them.
clawhub.json:7Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk
trader.py:73Declared Live-Trading Exposure Controls Are Not Fully Enforced
The skill explicitly requires a high-value credential (SIMMER_API_KEY) and is designed to place trades, but it does not declare a tool/permission scope limiting access to environment-derived secrets or execution capabilities. In an agent platform, missing explicit scope boundaries increases the chance the skill can access or misuse credentials beyond what operators expect, especially if later paired with executable code.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
F1 driver championship winner probabilities on Polymarket systematically deviate from a 100% total because of three structural mechanisms:
1. **Retail trades drivers individually** -- users buy YES on their favorite driver without checking whether the field total already exceeds 100%. A wave of enthusiasm after a race result inflates the winner without deflating the rest.
2. **No cross-market consistency enforcement** -- unlike a traditional bookmaker who adjusts the entire field when one runner's odds move, Polymarket has no market maker enforcing that the sum of all driver probabilities stays at 100%. Each driver is a separate order book with independent liquidity.
3. **Driver entry and exit creates transient imbalances** -- when a new driver is added to the championship market (mid-season replacement, rookie promotion) or a driver is removed (retirement, disqualification), the existing prices do not instantly re-normalize. The sum drifts until enough traders notice and correct it.
This manifest declares a required sensitive environment variable, SIMMER_API_KEY, indicating the skill will access credentials at runtime. In this file there is no accompanying warning or disclosure explaining that the skill uses an API key, which is relevant to user privacy and account safety.
No suspicious patterns detected.