T08 · Insecure Dependencies
- Location
SKILL.md:40- Finding
Unpinned Third-Party Dependency Has Access to Trading Credentials and Operations
- Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue, live=live) return _client ``` ### Technical Analysis The project instructs users and the Skill platform to install `simmer-sdk` without a fixed version or package-integrity hash. This permits the dependency resolver to install a future release whose contents may differ from the release reviewed with this Skill. The dependency executes inside the same Python process as the Skill. It is passed `SIMMER_API_KEY` directly and implements authenticated portfolio retrieval, position access, mark ...[truncated 1780 chars]- Remediation
View remediation
