T09 · Insecure Skill Coding Practices
- Location
copytrading_trader.py:238- Finding
Server-generated trade plans execute without local policy enforcement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real copy-trading skill with live financial authority, but its selling behavior and trade-safety boundaries are not disclosed or enforced clearly enough.
Install only if you are comfortable giving this skill authority over a low-value, tightly limited trading account. Use dry-run first, prefer $SIM paper trading, avoid exposing a broad wallet private key, and do not rely on the documentation's 'buy only' wording unless you explicitly disable whale exits with --no-whale-exits and verify behavior before using --live.
copytrading_trader.py:238Server-generated trade plans execute without local policy enforcement
SKILL.md:89Documentation conceals default whale-exit selling behavior and references a nonexistent option
requirements.txt:1Unbounded third-party SDK dependency handles API credentials, wallet signing, and trades
The skill documentation describes automated copytrading, wallet aggregation, and trade execution, but the detected behavior is read-only portfolio and position inspection. This mismatch is dangerous because operators may grant higher trust, permissions, or financial authority based on the stated purpose, while the actual implementation does something materially different, undermining reviewability and creating room for future bait-and-switch changes.
The manifest requires a SIMMER_API_KEY for copy-trading but provides no user-facing warning that the skill can initiate financially impactful actions using that credential. Because the skill mirrors external wallets and sizes trades automatically, users may supply a sensitive credential without understanding that it enables live market activity and potential financial loss.
The skill advertises commands that rely on environment-backed secrets and trading capability, but it does not declare an explicit tool scope such as allowed tools or permissions. That creates an authorization ambiguity: an agent or runtime may expose environment access more broadly than intended, increasing the chance of secret access or unintended trading-related execution paths.
The manifest declares a managed automaton entrypoint for an automated copy-trading skill, but it does not define clear invocation constraints, trigger scope, or user-consent boundaries. In a financial trading context, unconstrained automation materially increases the chance of unintended trade execution, repeated runs, or operation under conditions the user did not explicitly authorize.
The dependency is specified with a lower-bound only version constraint, which allows installation of any newer release of simmer-sdk, including unreviewed or potentially compromised versions. In a trading-related skill that interacts with external APIs and may influence financial actions, supply-chain compromise or breaking changes in a future package release could materially affect behavior and integrity.
simmer-sdk>=0.9.19
No suspicious patterns detected.