Back to skill

Security audit

CAI: connect-polymarket-with-cai

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed CAI-to-Polymarket connector, but it allows overly broad CAI API access and a raw wallet private-key fallback that users should review carefully before installing.

Install only if you are comfortable connecting a CAI account to Polymarket and giving the agent access to related platform tools. Prefer the narrowest platform-specific CAI credential, avoid full API scope unless CAI clearly requires it for this exact task, and do not paste wallet private keys or seed phrases into chat or generic tool fields; use a website or wallet-controlled flow instead.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:3
Finding

Overprivileged Full API Scope Permitted for Platform Connection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 3
Vulnerability Type: Excessive API authorization scope
Risk Level: Medium

Complete Code Snippet:

yaml
description: Connect Polymarket to your CAI account using platforms_supported_list and platform_one_click_register when F-16 applies; wallet derivation via catalog driver. Requires platform or full API scope. Powered by CAI.com.

Technical Analysis

The skill expressly permits use of a credential with either platform scope or full API scope. The documented workflow requires platform discovery, account registration, profile or balance retrieval, and vault credential metadata access, but it does not identify any operation that requires unrestricted account-wide API authorization.

Allowing full API scope violates the principle of least privilege. The skill also does not instruct the agent to prefer platform scope, reject unnecessarily broad credentials, or obtain separate user approval before escalating authorization.

Attack Path

  1. A user follows the skill and authorizes a CAI API credential with full API scope.
  2. The credential becomes available to the agent or associated integration.
  3. The agent environment, integration, or credential is compromised or misused.
  4. The attacker invokes API functionality outside the Polymarket connection workflow using the unnecessarily broad authorization.
  5. Unrelated CAI resources or operations accessible to that credential may be exposed or modified.

Impact Assessment

Successful exploitation could grant access beyond the Polymarket integration's legitimate requirements. The exact accessible resources depend on CAI's definition of full API scope, which is not specified in the audited file. The potential blast radius nevertheless exceeds the documented platform-linking task and could include unrelated account data or operations available through the same API credential.

Remediation
View remediation

Remediation Suggestions

  • Require the narrowest platform-specific authorization scope by default.
  • Remove the statement that full API scope is an acceptable general alternative.
  • Enumerate the exact permissions needed for platform discovery, registration, profile access, balance access, and credential metadata access.
  • Validate the credential's effective scope before beginning the workflow and reject credentials with unnecessary permissions.
  • If an operation genuinely requires broader access, request it through a separate, explicit, purpose-bound user consent step.
  • Use short-lived, revocable credentials and provide instructions for revoking access after linking.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

Raw Wallet Private Key Permitted in Agent-Mediated Workflow

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19-24
Vulnerability Type: Unsafe handling of wallet private-key material
Risk Level: High

Complete Code Snippet:

markdown
1. `platforms_supported_list` with `q=polymarket` (or hostname).
2. Optional: `uars_profile_site` for structured hints.
3. If `connector_configured` (**F-16**): `platform_one_click_register` with `platform_id`.
   - **wallet_derive:** may use custodial derivation when gateway profile exists; else one-time `private_key` per skill (not stored) or website flow.
4. After link: `platform_get_user_data` (balance, profile scope).
5. Vault metadata via `vault_list_platform_credentials` — **never** echo secrets in chat.

Technical Analysis

The workflow permits a one-time raw private_key when custodial wallet derivation is unavailable. A wallet private key is a bearer secret that can authorize transactions and provide control over associated assets.

The statement that the key is “not stored” is not backed by an enforceable technical control in the audited project. If supplied through an agent conversation or generic tool invocation, the key may enter model context, invocation records, telemetry, exception output, shell history, or infrastructure logs. The later instruction never to echo secrets does not protect the key while it is being collected or transmitted.

No executable implementation is included in the project, so persistent storage or actual disclosure cannot be confirmed. The vulnerability is the documented authorization of a high-impact secret-handling path without an isolated, non-model secret channel.

Attack Path

  1. Custodial wallet derivation is unavailable for a user.
  2. The skill follows the documented fallback and requests or accepts a raw wallet private key.
  3. The key passes through the agent or a generic integration channel.
  4. The key is retained in conversation context, tool logs, telemetry, er ...[truncated 785 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the raw private_key fallback from the agent workflow.
  • Explicitly instruct users never to paste wallet seed phrases or private keys into chat, prompts, command arguments, or generic tool fields.
  • Use a user-controlled wallet connection protocol in which the wallet signs a scoped challenge without disclosing private-key material.
  • Require transaction-specific approval through a browser wallet, mobile wallet, or hardware wallet.
  • If secret import is unavoidable, use a separately audited, isolated secret-entry interface whose values are never exposed to the model, logs, telemetry, or command history.
  • Redact sensitive fields at every logging boundary and test that errors cannot serialize secret values.
  • Prefer short-lived delegated credentials with narrowly defined permissions over reusable wallet keys.
  • Document revocation, wallet-disconnection, and incident-response procedures for suspected credential exposure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.