T08 · Insecure Dependencies
- Location
SKILL.md:80- Finding
Unpinned Third-Party Dependencies Execute in a Credential-Bearing Trading Environment
- Content
View full analysis
=0.28.0" httpx "websocket-client>=1.9.0" orjson pandas python-dotenv ``` `GUIDE.md:1010`: ```bash pip install "py-clob-client>=0.28.0" httpx "websocket-client>=1.9.0" orjson pandas python-dotenv ``` ### Technical Analysis The installation instructions leave `httpx`, `orjson`, `pandas`, and `python-dotenv` entirely unpinned. The constraints for `py-clob-client` and `websocket-client` only specify minimum versions and therefore also permit unreviewed future releases. Python packages and their installation hooks execute code in the local environment. In this Skill, that environment is expected to contain `POLYMARKET_PRIVATE_KEY`, CLOB API credentials, Builder API credentials, and authority to submit financial orders. Consequently, dependency integrity is a critical security boundary. The project provides no lockfile, package hashes, trusted-index restriction, or reproducible dependency manifest. This does not establish that any currently named package is malicious, but it permits a compromised or unexpectedly changed future release to be installed without further review. ### Attack Path 1. An attacker compromises a permitted package release or its publishing account. 2. A user or Agent follows the documented `pip install` command. 3. Package installation or import executes attacker-controlled Python code. 4. The malicious code reads environment variables or plaintext `.env` files containing wallet and API credentials. 5. The code exfiltrates those credentials, changes contract or API destinations, manipulates signed orders, or directly invokes available trading APIs. 6. The attacker uses the exposed authority to submit unauthorized orders or otherwise compromise the trading account. ### Impact Assess ...[truncated 687 chars]- Remediation
View remediation
