T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Trading SDK Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This trading skill is mostly transparent about its purpose, but its live-trading safety controls do not fully match what it promises.
Review before installing. Use only a low-limit or simulation-only API key unless the risk controls are fixed, pin or lock the SDK dependency, and do not rely on the documented volume, threshold, or open-position limits to cap real exposure in live mode.
clawhub.json:3Unpinned Trading SDK Creates a Supply-Chain Risk
trader.py:326Declared Trading Risk Controls Are Not Enforced
trader.py:63Global Client Cache Can Reuse Live Trading Mode During a Paper Run
The skill describes behavior that handles trading plumbing, requires a high-value API credential, and references capabilities consistent with environment access and file writing, yet it declares no explicit tool scope or permission boundaries. In an agent setting, missing scope declarations can allow broader-than-expected access to credentials or local files, increasing the blast radius if the skill is misused or composed with other automation.
No suspicious patterns detected.