T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Trading SDK Creates a Supply-Chain and Credential Exposure Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed trading skill, but its live-trading path has safety gaps that could place real-money trades in unintended markets or exceed the documented position limit.
Review carefully before installing, especially if you intend to use --live. Use a dedicated low-limit Simmer/Polymarket API key, keep the skill in paper mode until market matching and portfolio-limit enforcement are improved, and pin or otherwise verify simmer-sdk before giving it credentials.
clawhub.json:3Unpinned Trading SDK Creates a Supply-Chain and Credential Exposure Risk
trader.py:480Ambiguous Substring Matching Can Execute Trades on the Wrong Market
trader.py:466Documented Concurrent-Position Limit Is Not Enforced Across Runs
The skill description frames the behavior as tracking and following hot wallets, but the file documents materially broader capabilities: market discovery, independent signal generation, external API usage, and actual trade execution when run live. This mismatch is dangerous because operators may approve or invoke the skill under a narrower trust model than its real behavior, leading to unexpected financial actions and external data flows.
The skill declares no explicit tool scope or permissions even though its documented behavior requires environment access and network/API interaction. That creates an authorization and transparency gap: a user or platform may treat the skill as low-risk documentation while it can actually access secrets and external services, increasing the chance of unintended data exposure or unreviewed outbound actions.
This JSON manifest is in scope for missing-warning review because it is a markdown/manifest-style skill descriptor, and it explicitly requires the sensitive environment variable SIMMER_API_KEY. The file provides no accompanying disclosure that the skill uses credentials to access an external service or may place trades on the user's behalf, which is material to user privacy and system/account integrity.
No suspicious patterns detected.