Back to skill

Security audit

Polymarket Valuation Divergence

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading template that can place live Polymarket trades only when explicitly run with live mode, but users should treat the API key and unpinned SDK dependency carefully.

Install only if you are comfortable giving this skill a Simmer API key that can read account data and, with --live, place trades. Start in dry-run mode, use a dedicated low-limit or read-only key where possible, pin and review simmer-sdk before use, and remember that non-Simmer probability models require editing the code first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:6
Finding

Unpinned Third-Party SDK Receives Trading Credentials and Account Authority

Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue) ``` ### Technical Analysis The Skill declares and recommends installation of `simmer-sdk` without an exact version, cryptographic hash, or lock file. It then imports that package into the trusted process and provides it with the `SIMMER_API_KEY`. Imported Python packages execute arbitrary module-level code under the privileges of the current process. The SDK is also used to retrieve portfolio information and, when `--live` is supplied, submit real-money trades. Consequently, the dependency is placed within a highly sensitive trust boundary. The SDK is necessary for the declared trading functionality, and the repository does not contain evidence that the current package is malicious. The vulnerability is the absence of controls ensuring that the installed implementation is the same implementation that was reviewed. A c ...[truncated 2243 chars]
Remediation
View remediation
"] ``` 2. Maintain a lock file containing cryptographic hashes and install with hash verification, for example: ```bash pip install --require-hashes -r requirements.txt ``` 3. Obtain packages only from an explicitly configured trusted index. Disable unexpected extra indexes to reduce dependency-confusion risk. 4. Verify the package publisher, source repository, release provenance, signatures, and build artifacts before approving updates. 5. Perform dependency upgrades through a controlled review process. Re-audit SDK changes affecting authentication, endpoint selection, portfolio access, or trade execution. 6. Use a dedicated API key with the minimum required permissions. Prefer read-only credentials for dry runs and position display, and use a separate live-trading key only when `--live` is requested. 7. Apply server-side account controls where available, including maximum order size, daily loss limits, venue restrictions, withdrawal prohibition, and rapid credential revocation. 8. Run the Skill in an isolated environment with restricted filesystem access, a minimal environment-variable set, and outbound network access limited to verified service endpoints. 9. Avoid exposing the live key to dependency code during paper mode. Construct a read-only client or use unauthenticated market data when supported. 10. Document the SDK's expected network destinations and validate that credentials are never transmitted to unrelated hosts. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill overclaims support for arbitrary user/external probability models while the documented implementation appears to rely on Simmer AI consensus unless manually edited, and it also uses undeclared persistent config and position-view capabilities. This mismatch can mislead users about what external data is consumed, what local state is modified, and what account information is accessed, undermining informed consent and safe deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill overclaims support for arbitrary user/external probability models while the documented implementation appears to rely on Simmer AI consensus unless manually edited, and it also uses undeclared persistent config and position-view capabilities. This mismatch can mislead users about what external data is consumed, what local state is modified, and what account information is accessed, undermining informed consent and safe deployment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permissions even though the metadata and documented behavior imply access to environment variables, file writes, and networked trading/API operations. In an agent ecosystem, missing scope declarations reduce transparency and can allow a user or orchestrator to invoke a skill with broader capabilities than expected, increasing the risk of unintended data exposure or unauthorized actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the trader 'Works with any probability model (Simmer AI consensus, user model, external API),' implying pluggable or multiple probability sources. In code, get_model_probability only handles PROBABILITY_SOURCE == "simmer_ai" and returns None for all other configured sources, so the advertised broader model support is not actually implemented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.