T08 · Insecure Dependencies
- Location
clawhub.json:3- Finding
Unpinned Third-Party Dependency Receives a Live API Key
- Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue, live=live) ``` ### Technical Analysis The project declares and recommends installing `simmer-sdk` without an exact version, package hash, lockfile, or verified source constraint. Package resolution can therefore select different releases over time. Python executes the dependency during import, and the application subsequently passes `SIMMER_API_KEY` to dependency-controlled code. This creates a supply-chain trust boundary: the reviewed project does not control the code that handles the credential, performs network requests, loads and updates configuration, and initiates live market imports. A compromised, malicious, or unexpectedly changed future package release could execute arbitrary Python code with the same operating-system privileges as the Skill. The audit found no evidence that the current dependency is malicious. Exploitation depends on compromise, replac ...[truncated 1645 chars]- Remediation
View remediation
"] ``` ```bash pip install simmer-sdk== ``` 2. Generate and commit a dependency lockfile containing cryptographic hashes. Install with hash verification, such as: ```bash pip install --require-hashes -r requirements.txt ``` 3. Obtain packages only from an explicitly configured and trusted package index. Disable unintended fallback indexes to reduce dependency-confusion risk. 4. Review the selected package release and its transitive dependencies before updating the pin. Use automated dependency scanning and require controlled review for version changes. 5. Run the Skill under a dedicated, least-privileged operating-system account or sandbox. Restrict filesystem access and outbound network destinations to those required for Simmer operations. 6. Scope `SIMMER_API_KEY` to the minimum necessary permissions and quota. Avoid exposing unrelated credentials to the process environment. 7. Rotate the API key if an untrusted or unverifiable dependency version has previously been installed or executed. ]]>
