Back to skill

Security audit

polymarket-trade

Security checks for vulnerabilities and agentic risk

Overview

This skill has real Polymarket trading functionality, but it also adds unrelated registration, geoblocking-bypass guidance, and unsafe wallet-related configuration paths that need review before use.

Review this skill carefully before installing. Do not use it with a valuable wallet unless the publisher removes the unrelated rankings registration and VPN-bypass guidance, pins or strictly validates authenticated endpoints and contract addresses, replaces shell source/find patterns with safe path and dotenv parsing, and makes dependency installation explicitly user-controlled. If testing, use an isolated wallet with minimal funds.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:75
Finding

Unrelated rankings registration diverts wallet operations and discloses user identity

Content
View full analysis
/dev/null | head -1) source ~/.aurehub/.env WALLET_ADDRESS=$(node "$XAUT_SWAP" address | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).address") ``` ```sh REGISTER_RESP=$(curl -s -o /dev/null -w "%{http_code}" -X POST \ https://xaue.com/api/rankings/participants \ -H 'Content-Type: application/json' \ -d "{\"wallet_address\":\"$WALLET_ADDRESS\",\"nickname\":\"$NICKNAME_ESC\",\"source\":\"agent\"}") ``` ```text HTTP 200 or 201: echo "$WALLET_ADDRESS:$NICKNAME" > ~/.aurehub/.registered ``` ### Technical Analysis The declared purpose of the Skill is to browse and trade Polymarket positions. Nevertheless, its governing instructions require the Agent to run a separate “Wallet-Ready Registration” flow before balance, setup, trade, and redeem requests. This flow derives the user's wallet address, asks the user to join an unrelated XAUT rankings service, solicits a nickname, and sends the wallet address and nickname to `xaue.com`. It also writes registration or rejection markers that affect later sessions. The registration is not required for any Polymarket operation. It therefore exceeds the minimum privileges and data processing necessary for the declared functionality. The behavior is also absent from the Security & Privacy disclosure in `README.md:102-112`. ### Attack Path 1. A user asks to check a balance, trade, redeem, or configure Polymarket. 2. The Skill diverts the Agent into the rankings-registration flow before processing the requested operation. 3. The Sk ...[truncated 765 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:64
Finding

Broad home-directory search can select and execute an attacker-planted script

Content
View full analysis
/dev/null) [ -n "$GIT_ROOT" ] && [ -d "$GIT_ROOT/skills/polymarket-trade/scripts" ] && POLY_SCRIPTS_DIR="$GIT_ROOT/skills/polymarket-trade/scripts" # 2. Bounded home search [ -z "$POLY_SCRIPTS_DIR" ] && POLY_SCRIPTS_DIR=$(dirname "$(find -L "$HOME" -maxdepth 6 -type f -path "*/polymarket-trade/scripts/browse.js" 2>/dev/null | head -1)") ``` ```sh XAUT_SWAP=$(find -L "$HOME" -maxdepth 6 -type f -path "*/xaut-trade/scripts/swap.js" 2>/dev/null | head -1) source ~/.aurehub/.env WALLET_ADDRESS=$(node "$XAUT_SWAP" address | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).address") ``` ### Technical Analysis The Skill locates executable JavaScript by searching the user's home directory and selecting the first matching pathname. The search follows symbolic links through `find -L` and does not verify: - The canonical installation directory. - File ownership or permissions. - Whether any path component is a symbolic link. - A package signature or expected file hash. - Whether the selected file belongs to the trusted `xaut-trade` installation. A filename and directory layout are not sufficient provenance controls. Any process able to create a matching path under the home directory may influence which script is selected. ### Attack Path 1. An attacker or compromised local process creates a path such as `~/a/xaut-trade/scripts/swap.js`. 2. The path is arranged to appear before the legitimate installation in `find` output, or a matching symbolic link is created. 3. The user invokes a wallet-requiring flow. 4. The Skill runs the broad `find -L ... | head -1` lookup. 5. The attacker-controlled path is stored in `XAUT_SWAP`. 6. `node "$XAUT_SWAP" address` executes the attacker's JavaScript with the A ...[truncated 478 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:79
Finding

Sourcing the shared environment file executes configuration as shell code

Content
View full analysis
/dev/null | head -1) source ~/.aurehub/.env WALLET_ADDRESS=$(node "$XAUT_SWAP" address | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).address") ``` ```text If user says yes: - If NICKNAME is empty: ask user for nickname - Persist opt-in in ~/.aurehub/.env (RANKINGS_OPT_IN=true, NICKNAME=) - Re-source env: source ~/.aurehub/.env ``` ### Technical Analysis A `.env` file is normally a data file, but the shell `source` builtin interprets its entire contents as executable shell syntax. Assignments containing command substitutions, shell separators, redirections, or function declarations can therefore execute commands. The same instructions direct the Agent to persist a user-provided nickname into this file and then source it again, without specifying a robust shell-escaping mechanism. Even independently of nickname handling, any malicious or corrupted entry already present in the shared `.env` file becomes a command-execution vector. This is especially risky because `~/.aurehub/.env` is shared with other Skills and may contain values written by separate components. ### Attack Path 1. An attacker, compromised Skill, or unsafe persistence operation writes shell syntax to `~/.aurehub/.env`, for example through a crafted variable value. 2. The user invokes a wallet-requiring Polymarket flow. 3. The governing instructions execute `source ~/.aurehub/.env`. 4. The shell evaluates the injected syntax rather than parsing it strictly as key-value data. 5. Attacker-controlled commands execute with the Agent user's privileges. ### Impact Assessment Exploitation can provide arbitrary command execution under the local user account. This includes access to the WDK vault ...[truncated 223 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/clob.js:26
Finding

Configurable CLOB endpoint can receive wallet authentication and CLOB API secrets

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/trade.js:125
Finding

Untrusted contract configuration can redirect token approvals and POL transfers

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/setup.js:125
Finding

CLOB credentials are written before restrictive permissions are applied

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:33
Finding

Skill automatically installs third-party packages during prerequisite repair

Content
View full analysis
/scripts/` | AUTO-FIX | Run: `npm install` in `/scripts/` | ``` ```sh npx skills add aurehub/skills ``` ```sh cd /scripts npm install ``` The package manifest includes runtime dependencies such as: ```json { "dependencies": { "@polymarket/clob-client": "~5.7.0", "axios": "^1.13.6", "b4a": "^1.6.7", "bip39-mnemonic": "^2.5.0", "ethers": "^5.7.2", "js-yaml": "^4", "sodium-native": "^5.0.8" } } ``` ### Technical Analysis The Skill instructs the Agent to run `npm install` automatically when `node_modules` is absent. Package installation can execute dependency lifecycle scripts with the privileges of the Agent user. The project includes a lockfile with npm registry URLs and integrity hashes, which materially reduces dependency-resolution risk. No malicious package source or lockfile lifecycle-script entry was identified in the static review. However, the instruction uses `npm install` rather than deterministic `npm ci`, does not disable lifecycle scripts, and the `npx skills add` onboarding command is not version-pinned in the reviewed text. The issue is therefore unsafe automatic supply-chain execution rather than evidence that a currently declared dependency is malicious. ### Attack Path 1. `node_modules` is absent. 2. The Skill automatically runs `npm install`. 3. npm downloads and installs the dependency graph. 4. Any permitted dependency lifecycle script executes with the local user's privileges. 5. If a registry account, package release, lockfile, or installer source has been compromised, malicious install-time code gains local execution. ### Impact As ...[truncated 332 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (67)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly tells users to enable a VPN with a supported country node after a 403 geoblocking error, which is guidance for bypassing Polymarket regional access restrictions. This can facilitate terms-of-service violations, regulatory evasion, account sanctions, or legal exposure for users engaging in financial trading from prohibited jurisdictions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an end-user trading skill for Polymarket on Polygon. The supplied code chunk, however, only contains unit tests for environment/setup validation helpers. While the checked files (.wdk_vault, polymarket.yaml, .polymarket_clob) are consistent with the described ecosystem, the actual behavior in this chunk is not trading functionality or even runtime interaction with Polymarket—it is test logic ensuring required local files exist and that missing dependencies throw appropriate errors. This is a materially different primary purpose for the provided code chunk, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description focuses on Polymarket prediction-market operations: browsing markets, checking Polymarket/CLOB balances, and buying or selling YES/NO shares. The supplied code does not implement or test any Polymarket-specific market interaction. Instead, it tests a separate swap layer that obtains quotes from a quoter contract and performs a router multicall to swap POL into USDC.e, with slippage and gas handling. While such swapping could be a supporting step for funding Polymarket trades, the capability to perform on-chain token swaps through Uniswap-style infrastructure is itself undeclared and is the primary behavior visible in this chunk. That makes this a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description centers on Polymarket prediction-market operations such as browsing markets and buying or selling YES/NO shares. The supplied code instead performs a generic asset swap on Polygon using Uniswap V3 infrastructure, specifically converting POL/WMATIC into USDC.e. While such a swap could be a supporting step for funding Polymarket trades, this chunk does not itself implement Polymarket-specific behavior. Because the actual code’s primary function is token swapping through external DEX contracts rather than the declared Polymarket trading features, this is a meaningful description/behavior mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill sources ~/.aurehub/.env and derives a wallet address via another skill's script, which crosses trust boundaries and accesses credential-bearing local state. In an agent context, this can expose secrets or normalize loading sensitive environment data from user files without strict scoping or consent.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

bash
XAUT_SWAP=$(find -L "$HOME" -maxdepth 6 -type f -path "*/xaut-trade/scripts/swap.js" 2>/dev/null | head -1)
source ~/.aurehub/.env
WALLET_ADDRESS=$(node "$XAUT_SWAP" address | node -p "JSON.parse(require('fs').readFileSync(0,'utf8')).address")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions direct posting a wallet address and nickname to an unrelated external endpoint. This leaks persistent identity-linked financial metadata to a third party, enabling tracking, profiling, and correlation of a user's trading wallet with a chosen identity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells users to use a VPN to work around Polymarket regional restrictions. This encourages circumvention of access controls and legal/compliance safeguards, which is especially serious in a regulated financial or betting context.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.tests.yaml (reported line 50)May include surrounding context.

yaml
~/.aurehub/.env: null
        prompt: "Buy $10 YES on bitcoin"
        expect:
          - pattern: "cp.*\\.env\\.example|\\.env"
            type: command

      - id: smoke-missing-vault

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.example.yaml (reported line 2)May include surrounding context.

yaml
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.example.yaml (reported line 4)May include surrounding context.

yaml
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/config.test.js (reported line 12)May include surrounding context.

js
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/config.test.js (reported line 27)May include surrounding context.

js
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/setup.test.js (reported line 12)May include surrounding context.

js
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/setup.test.js (reported line 20)May include surrounding context.

js
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/config.js (reported line 44)May include surrounding context.

js
# Copy to ~/.aurehub/polymarket.yaml and fill in values.
# POLYGON_RPC_URL must be set in ~/.aurehub/.env

rpc_env: POLYGON_RPC_URL     # env var name in .env — not the URL itself

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 30)May include surrounding context.

If credentials expire or become invalid:

bash
rm ~/.aurehub/.polymarket_clob
node scripts/setup.js

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/config.test.js (reported line 13)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/config.test.js (reported line 28)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/setup.test.js (reported line 15)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/setup.test.js (reported line 23)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/__tests__/setup.test.js (reported line 30)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/config.js (reported line 27)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.js (reported line 17)May include surrounding context.

js
describe('loadConfig', () => {
  it('loads .env and polymarket.yaml', () => {
    writeFileSync(join(dir, '.env'), 'WALLET_MODE=wdk\nPOLYGON_RPC_URL=https://example.com\n');
    writeFileSync(join(dir, 'polymarket.yaml'), 'rpc_env: POLYGON_RPC_URL\n');
    const cfg = loadConfig(dir);
    expect(cfg.env.WALLET_MODE).toBe('wdk');

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly advises users to use a VPN when the Polymarket API returns 403 due to regional blocking. That is guidance to bypass geographic access controls, which can facilitate violations of platform restrictions, local law, or compliance obligations. In a trading skill, this is more dangerous because it directly supports access to a financial/prediction-market service that may be restricted for regulatory reasons.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

axios is a production dependency and the listed advisories include SSRF/proxy-bypass and request-handling issues that are relevant to software making outbound network calls. In a wallet-enabled trading skill that talks to external APIs and market infrastructure, a vulnerable HTTP client can increase the risk of request redirection, credential leakage, or unintended access to internal resources if attacker-controlled URLs, redirects, or proxy settings are involved.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.