T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned High-Trust Trading SDK Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed real-money trading bot, but it deserves Review because it can run unattended live trades and relies on high-trust credentials and dependencies with weak safeguards.
Review this carefully before installing. Use a dedicated low-limit trading key, run paper mode first, avoid cron until you understand the strategy, do not use `--no-safeguards` casually, pin and review `simmer-sdk`, and only configure a trusted HTTPS Discord webhook destination. The current script also appears broken because a missing `max_consecutive_losses` config key causes startup failure.
clawhub.json:3Unpinned High-Trust Trading SDK Dependency
btc_midcandle.py:303Unrestricted Webhook Destination Permits Blind Server-Side Requests
The documented purpose understates the skill's effective capabilities by omitting external Binance data access, Discord webhook exfiltration paths, local state persistence, and broader account/position management functions. That mismatch is dangerous because users may approve a trading strategy while unknowingly granting network, persistence, and account-management behaviors that materially expand the attack surface and operational risk.
The skill advertises operational behavior that implies access to environment variables, local files, and network services, but it does not declare any tool scope or permissions boundary. In an agent ecosystem, that omission prevents users and platforms from understanding or constraining what the skill can access, increasing the risk of over-privileged execution and unintended data or trading actions.
The skill documents real-money trading and an explicit '--no-safeguards' mode, but the warning language is not strong or specific enough for commands that can directly cause financial loss. In this context, normalizing a protection-bypass flag without prominent risk disclosure can lead operators to disable controls they do not fully understand, increasing the chance of runaway or unsafe trading behavior.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
crontab -e
Add:
The documentation advertises --set configuration updates, but in fallback mode update_config is never defined and the code only catches the resulting exception after presenting the feature as supported. This is primarily a trust/safety issue: operators may believe risk controls like bet sizing were changed when they were not, leading to unintended live-trading behavior.
The --live flag enables real-money trading immediately with no interactive confirmation, cooldown, or secondary safety check. In an automation context, a typo, copied command, or malicious wrapper invocation can cause unintended live trades with direct financial impact.
The code references _config["max_consecutive_losses"], but that key is not defined in CONFIG_SCHEMA, so the script will raise a KeyError at import time before any trading logic runs. In a real-money trading skill, this creates a reliable denial-of-service condition and indicates incomplete or unsafe state/risk-control code paths.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return in_window, mins_remaining, candle_start
def binance_klines(interval, limit, retries=2):
url = f"https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval={interval}&limit={limit}"
for attempt in range(retries):
try:
req = _ur.Request(url, headers={"User-Agent": "simmer-btcmc/1.0"})
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return in_window, mins_remaining, candle_start
def binance_klines(interval, limit, retries=2):
url = f"https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval={interval}&limit={limit}"
for attempt in range(retries):
try:
req = _ur.Request(url, headers={"User-Agent": "simmer-btcmc/1.0"})
When DISCORD_WEBHOOK is configured, the skill silently sends trade details to an external Discord endpoint without prominent runtime disclosure near the operation. This can leak trading behavior, positions, and market activity to third parties, which is especially sensitive for automated real-money strategies.
Although the script describes paper trading as the default, run_strategy() calls get_client(live=not dry_run) even in dry-run mode, which still requires SIMMER_API_KEY and initializes a network client. This undermines operator expectations and can expose credentials or trigger unnecessary external connectivity in contexts assumed to be safe for offline testing.
No suspicious patterns detected.