T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Trading SDK Creates Supply-Chain Exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a clearly described trading bot, but its live-trading safeguards are weaker than documented and could expose real funds to unintended risk.
Install only if you are comfortable reviewing and fixing the trading controls before using live mode. Keep it in paper mode unless the SDK dependency is pinned and the volume, slippage/context, and account-position limits are enforced against real account state. Use a restricted API key and small limits for any live testing.
clawhub.json:3Unpinned Trading SDK Creates Supply-Chain Exposure
trader.py:414Configured Minimum Market Volume Safeguard Is Not Enforced
trader.py:310Trading Context Safeguard Fails Open on Errors
trader.py:413Maximum Position Limit Counts Only Orders Placed During the Current Run
The skill references a high-value environment credential (SIMMER_API_KEY) and trading functionality, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent runtime, this can grant broader-than-necessary access to environment data and make it harder to enforce least privilege, increasing the chance of credential exposure or misuse if the skill is modified or composed with other capabilities.
No suspicious patterns detected.