Back to skill

Security audit

Polymarket BTC Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill can place real-money trades and exposes trading controls and account data through an unauthenticated web panel while its documentation inconsistently describes paper trading.

Review carefully before installing. Use a segregated, low-balance wallet and test environment only, do not expose the panel to a network, rotate any keys placed into this package, and require authentication plus explicit live-trading opt-in before running it with real funds.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
status_server.py:510
Finding

Unauthenticated Network-Exposed Trading Control

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
status_server.py:595
Finding

Unauthenticated Disclosure of Wallet, Balance, Positions, Trades, and Strategy Data

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
status_server.py:802
Finding

Unauthenticated GET Endpoint Performs Destructive Trading-State Mutation

Content
View full analysis
0) losses = sum(1 for t in all_closed if t.get("realized_profit", 0) < 0) total = len(all_closed) cash = current.get("cash_balance", 0) starting = 100.0 computed_pnl = cash - starting current["trades"] = all_trades current["starting_balance"] = round(starting, 4) current["realized_pnl"] = round(computed_pnl, 4) current["stats"]["total_trades"] = total current["stats"]["winning_trades"] = wins current["stats"]["losing_trades"] = losses current["stats"]["total_profit"] = round(computed_pnl, 4) current["summary"]["starting_balance"] = round(starting, 4) current["summary"]["realized_ ...[truncated 1979 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/public/status.js:1217
Finding

DOM Injection Through Unescaped Third-Party API Values

Content
View full analysis
{ const prob = ((o.current_probability || 0) * 100).toFixed(1); const div = ((o.divergence || 0) * 100).toFixed(1); const side = o.recommended_side === 'yes' ? 'YES' : 'NO'; const sideClass = o.recommended_side === 'yes' ? 'tag-buy' : 'tag-sell'; const exp = o.resolves_at ? shortTime(o.resolves_at) : '--'; return ` ${escapeHtml(truncate(o.question, 40))} ${prob}% ${side} ${div > 0 ? '+' : ''}${div}% ${exp} `; }).join(''); ``` ```javascript tbody.innerHTML = positions.map(p => { const prob = ((p.current_probability || 0) * 100).toFixed(1); return ` ${escapeHtml(truncate(p.question || p.market_question || '—'), 35)} ${p.side?.toUpperCase()} ${p.shares || 0} ${formatUSD(p.value || 0)} `; }).join(''); ``` ```javascript const data = await res.json(); if (!res.ok) throw new Error(data.error || data.message || 'Trade failed'); resultEl.innerHTML = `Successful purchase of ${data.shares_bought || '?'} shares`; setTimeout(loadSimmerData, 2000); ``` ```javascript } catch(e) { resultEl.innerHTML = `${e.message}
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install.sh:23
Finding

Unpinned and Incomplete Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (85)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

前端代码直接内置 Bearer Token 并向外部 Simmer API 发起认证请求,这意味着任何访问页面的人都可以从浏览器源码或网络请求中提取该凭证。若该凭证对应真实账户或可交易权限,攻击者可复用它读取敏感账户信息、发起交易或滥用配额,造成直接资金与数据风险。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

该代码提供了从 UI 直接向外部 Simmer /trade 接口提交真实交易请求的能力,且同样使用前端可见的认证令牌。任何能够操作页面或注入脚本的主体都可能借此触发未授权下单,直接导致资金损失。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README presents the bot as 'paper trading' and 'not spending real USDC', yet elsewhere it requires live Polymarket API credentials and describes real on-chain trading. This kind of safety-signaling mismatch can mislead users into granting real account access under a false assumption of no financial risk, which materially increases the chance of unintended live trading or exposure of funded credentials.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Claiming that no real USDC is used while later implying a valid balance-sensitive Polymarket account and API access creates a deceptive operational picture. Users may connect real wallets or funded accounts believing they are safe, leading to financial loss, credential exposure, or unintended interaction with production trading infrastructure.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly advertises fully automated real trading and on-chain transactions but does not present a clear financial-risk warning or live-funds warning. In this context, omission of that warning materially increases the chance of accidental loss, misuse in production, or users enabling automation without understanding capital risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

该文件在既有 Polymarket 机器人界面中额外嵌入了 Simmer 平台的数据读取与交易逻辑,功能范围明显超出技能声明。对用户和审计者而言,这种隐藏式扩权会造成错误信任边界,可能让操作者在不理解的情况下与第三方交易平台交互并暴露资金或策略数据。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

界面文案向用户声明“不会触发真实下单”,但同一文件同时实现了外部平台下单函数,这会误导用户对系统能力和风险边界的判断。在交易技能场景中,错误安全承诺会降低警惕,增加用户触发真实交易、泄露凭证或批准危险操作的概率。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

UI 可直接触发 live trade,但代码中没有看到用户确认、风险警告、金额复核或防误触机制。对于真实资产交易,这会显著提高误操作、脚本滥用和社工诱导点击后直接成交的风险。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The AI prompt explicitly frames the model as a paper-trading analyzer, but its output is later used to drive real on-chain trades. This mismatch is dangerous because it lowers operator expectations and can cause unsafe reliance on model output in a financially irreversible context.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · bot.py (reported line 917)May include surrounding context.

python
"bot_setting": [
                {
                    "bot_name": "TraderBot",
                    "content": "You are a helpful trading assistant. Always respond with valid JSON only, no explanations."
                }
            ],
            "reply_constraints": {

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bot executes live trading orders automatically using API credentials and private-key-backed signing without any runtime confirmation, approval workflow, or explicit safety interlock. In the context of a real-money trading skill, this materially increases the chance of unintended financial loss from logic bugs, bad data, model errors, or manipulated external inputs.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

md
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 43)May include surrounding context.

md
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bot.py (reported line 156)May include surrounding context.

python
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bot.py (reported line 1626)May include surrounding context.

python
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bot.py (reported line 1678)May include surrounding context.

python
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bot.py (reported line 1682)May include surrounding context.

python
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bot_start.sh (reported line 17)May include surrounding context.

sh
cp "$SKILL_DIR/status_server.py"         "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"*        "$WORK_DIR/public/"

# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
    cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
    echo "⚠️  已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"

Static analysis

No suspicious patterns detected.