T08 · Insecure Dependencies
- Location
clawhub.json:9- Finding
Security-Critical SDK Dependency Is Not Pinned to an Audited Version
- Content
View full analysis
=0.11.1" ] ``` The installation instructions in `SKILL.md:42-44` similarly install the latest package version satisfying the package name: ```bash pip install simmer-sdk ``` ### Technical Analysis The Skill permits any current or future `simmer-sdk` release greater than or equal to version `0.11.1`. There is no upper version boundary, dependency lockfile, integrity hash, or other mechanism binding installation to the version that was reviewed. This dependency is security-critical. The Skill imports and invokes it directly, passes the Simmer API key into `SimmerClient`, and documents that the SDK handles wallet signing when `WALLET_PRIVATE_KEY` is present. A compromised upstream release, publisher account, package distribution channel, or transitive dependency could therefore execute arbitrary Python code with the same privileges as the Skill. No evidence shows that the current SDK package is malicious. The vulnerability is the absence of controls preventing a future, substituted, or compromised release from silently changing the effective code executed by the Skill. ### Attack Path 1. An attacker compromises the package publisher, package repository, or a transitive dependency used by `simmer-sdk`. 2. The attacker publishes a malicious version satisfying `>=0.11.1`. 3. A user installs or updates the Skill using `pip install simmer-sdk`, which resolves to the compromised version. 4. The malicious package executes when imported or when `SimmerClient` is initialized. 5. It reads `SIMMER_API_KEY` and potentially `WALLET_PRIVATE_KEY` from the process environment. 6. It can transmit those credentials, alter market data, submit unauthorized trades, or execute arbitrary operations permitted to the Skill process. ### Impact Assessment Successful exploitation gran ...[truncated 725 chars]- Remediation
View remediation
" ] ``` 2. Update `SKILL.md` to install the same exact version. 3. Generate and retain a lockfile containing all transitive dependency versions. 4. Require package hashes during installation, for example through a hashed requirements file and `pip install --require-hashes`. 5. Verify package provenance and publisher identity before approving upgrades. 6. Review SDK release notes and security-sensitive changes before modifying the pinned version. 7. Run the Skill in an isolated environment with access only to required files, network destinations, and credentials. 8. Avoid exposing a wallet private key to the process when managed-wallet functionality is sufficient. ]]>
