T08 · Insecure Dependencies
- Location
clawhub.json:2- Finding
Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not deceptive, but it should be reviewed carefully because it can place real trades and some advertised risk controls are weak or not enforced.
Use this first in paper mode. Before any --live use, review or fix the risk-control gaps, pin and verify simmer-sdk, and use a narrowly scoped API key with only the trading authority you are willing to expose.
clawhub.json:2Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk
trader.py:285Live-Trading Context Safeguards Fail Open on Errors
trader.py:226Invalid Resolution Timestamps Bypass the Minimum-Time Safety Gate
trader.py:320Configured Liquidity and Concurrent-Position Limits Are Not Enforced
trader.py:244Minimum Trade Size Can Override the Maximum Position Limit
The skill references a high-value secret (SIMMER_API_KEY) and describes trading behavior, but it does not declare any explicit tool scope or permissions boundary. When a skill can access environment variables without a restrictive manifest, an agent runtime may overgrant access to secrets or capabilities beyond what the skill actually needs, increasing the blast radius if the skill is modified, misused, or compromised.
This manifest requires the SIMMER_API_KEY environment variable, which indicates the skill uses sensitive credentials. In this file there is no accompanying warning, description, or user-facing disclosure about credential use, and manifest files are in scope for missing-warning review when they are markdown only? However this file itself exposes the requirement semantically without any visible warning to the user about credential handling or external service access.
No suspicious patterns detected.