T09 · Insecure Skill Coding Practices
- Location
scripts/status.py:16- Finding
API Credential Can Be Redirected to an Arbitrary Network Host
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed trading skill, but it has material safety and scoping problems around API-key handling and live financial safeguards.
Install only if you are comfortable giving this skill a Simmer trading API key and reviewing its live-trading settings yourself. Keep it in dry-run until you verify the effective per-trade limit, daily budget, fee policy, and endpoint configuration; use a narrowly scoped revocable API key if possible.
scripts/status.py:16API Credential Can Be Redirected to an Arbitrary Network Host
ai_divergence.py:346Documented Zero-Fee Trading Safeguard Is Not Enforced
clawhub.json:3Privileged Trading SDK Dependency Is Not Version or Integrity Pinned
clawhub.json:22Managed Automation Defaults Exceed the Documented Trading Limits
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
f"{SIMMER_API_URL}/api/sdk/markets",
headers={"Authorization": f"Bearer {api_key}"}
)
data = json.loads(urlopen(req, timeout=30).read())
markets = data.get("markets", [])
high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]
The documented behavior claims autonomous trade execution, Kelly sizing, fee filtering, and safeguards, while the analyzed implementation apparently does not perform those controls and is primarily status reporting. This mismatch is dangerous because users may rely on nonexistent protections or assume orders are being screened for risk when they are not, creating a serious operational and financial safety issue.
The skill describes use of network access, environment variables, and live trading flows, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can lead to broader-than-expected access and make it harder for operators to review or constrain what the skill is allowed to do before execution.
The skill includes a command for live trade execution but does not present an explicit warning about financial loss, irreversible orders, or the need for user confirmation. In a trading context, that omission increases the chance of accidental real-money actions, especially when the documented interface makes switching from dry-run to live mode trivial.
The manifest defines an automated trading skill but provides no activation conditions, trigger constraints, or contextual gating on when it should run. In a financial-trading context, unconstrained invocation increases the chance of unintended or excessive trade execution, especially if another component can invoke the skill opportunistically or without sufficient user intent checks.
The natural-language labels and environment names embed a specific currency/locale assumption (for example, 'USD', 'Max bet per trade', and 'Daily budget') without indicating that this is optional or region-specific. That can violate language/locale policy if the skill is presented generally rather than as a clearly US-specific tool.
No suspicious patterns detected.