T08 · Insecure Dependencies
- Location
requirements.txt:4- Finding
Unpinned Dependencies Expose Security-Critical Trading Operations to Supply-Chain Risk
- Content
View full analysis
=10.0 websocket-client>=1.0.0 python-socketio>=5.0.0 # HTTP clients aiohttp>=3.8.0 requests>=2.28.0 # Environment variables python-dotenv>=0.20.0 ``` The security-critical trading SDK is also installed without a version constraint and is not declared in `requirements.txt` or `skill.json`: ```python # lib/polymarket_client.py:10-13 Installation: pip install py-clob-client ``` ```python # lib/polymarket_client.py:69-71 if not PY_CLOB_CLIENT_AVAILABLE: raise ImportError( "py-clob-client is required for real trading. " "Install with: pip install py-clob-client" ) ``` The SDK receives wallet authority and is used to derive trading credentials: ```python # lib/polymarket_client.py:96-105 client = ClobClient( host="https://clob.polymarket.com", key=self.private_key, chain_id=137, # Polygon mainnet signature_type=self.signature_type ) # Derive API credentials from private key creds = client.derive_api_key() return client, creds ``` ### Technical Analysis All declared dependencies use open-ended lower bounds. A command such as `pip install -r requirements.txt` can therefore resolve to future package releases that were not reviewed with this Skill. There is no lock file, exact version pin, or package hash to ensure reproducible and integrity-verified installation. The more sensitive `py-clob-client` dependency is omitted from the formal dependency manifests and is instead installed through an unrestricted `pip install py-clob-client` instruction. This package is particularly security-critical because the application passes the user's wallet private key to its `ClobClient` object and relies ...[truncated 2306 chars]- Remediation
View remediation
websocket-client== python-socketio== aiohttp== requests== python-dotenv== py-clob-client== ``` 2. Add `py-clob-client` to both `requirements.txt` and `skill.json` so the security-critical dependency is visible, reproducible, and covered by dependency review. 3. Generate and verify package hashes using a locked requirements file, for example with `pip-compile --generate-hashes`, and install with: ```bash pip install --require-hashes -r requirements.lock ``` 4. Install dependencies in an isolated virtual environment under a non-privileged operating-system account. 5. Review the selected `py-clob-client` release and its transitive dependencies before allowing it to receive a production wallet key. Monitor package ownership and release-signing changes. 6. Use a dedicated, low-balance trading wallet with narrowly scoped approvals rather than a primary wallet. Keep private keys outside source code and avoid retaining them longer than necessary. 7. Establish a controlled dependency-update process that includes vulnerability scanning, source review for security-sensitive updates, automated tests, and explicit approval before changing locked versions. ]]>
