T08 · Insecure Dependencies
- Location
clawhub.json:5- Finding
Unpinned Trading SDK Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real-money weather trading skill with disclosed core purpose, but its effective trading limits and local code-loading behavior are too broad for automatic trust.
Install only if you understand it can place real USDC trades and you are comfortable auditing the effective config first. Use a minimally scoped SIMMER_API_KEY, avoid running --live or --no-safeguards until defaults are corrected, pin simmer-sdk, and do not run this in a shared skill directory where sibling files could influence imports.
clawhub.json:5Unpinned Trading SDK Creates a Supply-Chain Risk
weather_trader.py:94Parent-Directory Module Preloading Allows Local Tool Hijacking
trade_performance.py:876Path Traversal in Auto-Tune Option Can Execute an Arbitrary Local Python Module
config.json:2Shipped Trading Configuration Weakens Documented Financial Safeguards
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.
The skill loads a project-root .env file automatically, which can unintentionally ingest secrets unrelated to this skill from a broader workspace. In multi-skill or shared environments, this expands secret exposure and makes it easier for imported modules or future code changes to access credentials that were never meant for this component.
from urllib.error import HTTPError, URLError
from urllib.parse import urlencode
# Load .env from project root (two levels up from this file)
try:
from dotenv import load_dotenv
Resolving and loading ../../.env creates cross-boundary secret access: the skill reaches outside its own directory and imports all variables from a higher-level file. In shared repositories, that can expose unrelated API tokens or operational credentials to this trading skill and any modules it imports, increasing blast radius if the skill is compromised or behaves unexpectedly.
try:
from dotenv import load_dotenv
_env_path = Path(__file__).resolve().parent.parent / ".env"
if _env_path.exists():
load_dotenv(_env_path)
except ImportError:
The skill advertises capabilities that inherently require network, file, and environment access, but it does not declare an explicit tool/permission scope. In an agent setting, missing scope boundaries makes it harder to enforce least privilege and increases the chance that a trading-oriented skill gets broader access than intended, especially given its documented read/write logging and live trading behavior.
The skill documents live real-money trading against Polymarket/USDC without a prominent warning that execution may be irreversible and financially risky. In a skill that can plausibly be invoked by non-experts, weak risk disclosure increases the likelihood of accidental fund loss or unintended live orders.
Advertising a --no-safeguards option without an explicit, strong warning normalizes disabling protective controls in a real-money trading system. That raises the chance of users running with slippage, circuit-breaker, or other protections bypassed, which can materially increase loss and unstable behavior.
The manifest does not define any explicit trigger scope, allowed invocation conditions, or narrowing constraints beyond descriptive text. For a trading skill that can place market orders via an API key, ambiguous activation increases the risk of unintended invocation by loosely related prompts, which could lead to unauthorized or accidental trades.
The help text states that --snapshot controls whether a snapshot is written, but the program writes a snapshot even when that flag is absent because of the later 'if args.snapshot or not args.quiet' logic. This mismatch can mislead users and downstream tooling into triggering unintended writes, which is a security-relevant integrity issue even if it does not enable code execution.
The script performs a filesystem write as part of normal reporting behavior, which violates the expected read-only semantics of a reporting utility. In this trading-skill context, silent mutation of local state can surprise operators, overwrite prior snapshots, and interfere with automation that assumes report generation is side-effect free.
The code writes performance_snapshot.json during ordinary execution without explicit user opt-in or a clear warning, creating an unexpected persistent side effect. In a skill that may be run by agents or scheduled jobs, this can lead to unanticipated file creation, state drift, and overwriting of prior data, increasing operational risk.
The --auto-tune path constructs a sibling skill path from user-controlled input, then dynamically loads and executes that trader module via importlib. That means running this reporting utility can execute arbitrary Python code from any sibling skill directory, expanding the trust boundary from this weather skill to adjacent local content and creating a code-execution primitive if an attacker can place or influence such a module.
This code automatically loads a project-root .env file and later consumes SIMMER_API_KEY for authenticated trading, which is a sensitive credential access path. Although the docstring lists the required variable, there is no runtime disclosure, confirmation, or warning that the skill will read credentials from local environment/.env sources before contacting trading APIs.
The manifest describes trading driven by NOAA and Open-Meteo forecasts, EV/Kelly sizing, Bayesian updates, and maker/taker switching. This file additionally fetches and merges external 'Smart Money' signals into trade decisions, which is a separate market-intelligence capability not declared in the stated purpose.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}
OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"
MAX_RETRIES = 2
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}
OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"
MAX_RETRIES = 2
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}
OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"
MAX_RETRIES = 2
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
if not station_id:
return {}
url = f"https://api.weather.gov/stations/{station_id}/observations/latest"
headers = {
"User-Agent": "SimmerWeatherSkill/1.0 (https://simmer.markets)",
"Accept": "application/geo+json",
The manifest says the skill can be used to configure locations/thresholds, and the code even loads a locations setting into ACTIVE_LOCATIONS. However, the main strategy always discovers broad weather markets and groups/trades all parsed events without filtering to configured locations, so configured locations do not actually constrain behavior.
No suspicious patterns detected.