T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Security-Sensitive Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Review item because it monitors Polymarket but also uses wallet secrets and automatically runs unbundled trading scripts that can spend funds without per-trade approval.
Only install this after reviewing or supplying the helper scripts yourself, using a dedicated low-balance wallet, pinning dependencies, and confirming that automatic trading is intentionally enabled. Do not put a main wallet private key or unrelated secrets in the same .env file, and do not run it from cron until spending limits and circuit-breaker behavior are clear.
SKILL.md:30Unpinned Security-Sensitive Third-Party Dependencies
monitor.py:131Private Key Used for a Read-Only Operation and Inherited by Child Processes
monitor.py:142Automatic Execution of Unbundled Financial-Action Scripts
monitor.py:49Local Circuit-Breaker State Can Be Reset or Unpaused During the Same Day
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
f"{DATA_API}/positions?user={wallet}&sizeThreshold=0.01&limit=100",
headers={"User-Agent": "ClawdipusRex/1.0"}
)
with urllib.request.urlopen(req, timeout=10) as r:
data = json.loads(r.read())
return data if isinstance(data, list) else data.get("data", [])
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
GAMMA_API = "https://gamma-api.polymarket.com"
def load_env():
env_path = Path(__file__).parent / ".env"
if env_path.exists():
for line in env_path.read_text().splitlines():
line = line.strip()
The skill advertises automatic reinvestment that can execute trades when available cash reaches a threshold, but it does not present a clear upfront warning that real funds may be committed without per-trade confirmation. In a financial trading context, this creates a meaningful risk of unintended asset deployment, especially when paired with cron-based unattended execution and integration with other trading scripts.
The file presents itself as a monitor, but it also automatically executes trading automation scripts that can place or manage positions. In a security review context, this concealment-by-omission is dangerous because operators may approve or schedule the skill expecting read-only behavior while it performs state-changing financial actions.
The top-level documentation explicitly claims 'Reports P&L to Telegram' as part of the skill's behavior. In the implementation, notifications are assembled and emitted with print statements only, with no Telegram API call, webhook, bot client, or message transport present.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd = ["python3", str(Path(__file__).parent / script)]
if extra_args:
cmd.extend(extra_args)
r = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
return (r.stdout + r.stderr).strip()
def main():
The module docstring states that P&L is reported to Telegram, presenting a fixed communication channel in natural language without indicating any user choice or opt-in. This is a mild policy concern because it prescribes a specific reporting medium rather than offering configurable notification preferences.
No suspicious patterns detected.