T05 · Unauthorized Access and Privilege Escalation
- Location
status_server.py:510- Finding
Unauthenticated Network-Exposed Trading Control
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill can place real-money trades and exposes trading controls and account data through an unauthenticated web panel while its documentation inconsistently describes paper trading.
Review carefully before installing. Use a segregated, low-balance wallet and test environment only, do not expose the panel to a network, rotate any keys placed into this package, and require authentication plus explicit live-trading opt-in before running it with real funds.
status_server.py:510Unauthenticated Network-Exposed Trading Control
status_server.py:595Unauthenticated Disclosure of Wallet, Balance, Positions, Trades, and Strategy Data
status_server.py:802Unauthenticated GET Endpoint Performs Destructive Trading-State Mutation
assets/public/status.js:1217DOM Injection Through Unescaped Third-Party API Values
scripts/install.sh:23Unpinned and Incomplete Third-Party Dependency Installation
前端代码直接内置 Bearer Token 并向外部 Simmer API 发起认证请求,这意味着任何访问页面的人都可以从浏览器源码或网络请求中提取该凭证。若该凭证对应真实账户或可交易权限,攻击者可复用它读取敏感账户信息、发起交易或滥用配额,造成直接资金与数据风险。
该代码提供了从 UI 直接向外部 Simmer /trade 接口提交真实交易请求的能力,且同样使用前端可见的认证令牌。任何能够操作页面或注入脚本的主体都可能借此触发未授权下单,直接导致资金损失。
The README presents the bot as 'paper trading' and 'not spending real USDC', yet elsewhere it requires live Polymarket API credentials and describes real on-chain trading. This kind of safety-signaling mismatch can mislead users into granting real account access under a false assumption of no financial risk, which materially increases the chance of unintended live trading or exposure of funded credentials.
Claiming that no real USDC is used while later implying a valid balance-sensitive Polymarket account and API access creates a deceptive operational picture. Users may connect real wallets or funded accounts believing they are safe, leading to financial loss, credential exposure, or unintended interaction with production trading infrastructure.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.
The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.
The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.
The finding indicates the description emphasizes fully automated on-chain trading, but the actual chunk instead includes undeclared data retrieval and local history modification endpoints without corresponding trade logic. In a live-trading setting, such mismatches hide the true attack surface and can expose sensitive wallet or trading data while misleading users about what the skill actually does.
The skill explicitly advertises fully automated real trading and on-chain transactions but does not present a clear financial-risk warning or live-funds warning. In this context, omission of that warning materially increases the chance of accidental loss, misuse in production, or users enabling automation without understanding capital risk.
该文件在既有 Polymarket 机器人界面中额外嵌入了 Simmer 平台的数据读取与交易逻辑,功能范围明显超出技能声明。对用户和审计者而言,这种隐藏式扩权会造成错误信任边界,可能让操作者在不理解的情况下与第三方交易平台交互并暴露资金或策略数据。
界面文案向用户声明“不会触发真实下单”,但同一文件同时实现了外部平台下单函数,这会误导用户对系统能力和风险边界的判断。在交易技能场景中,错误安全承诺会降低警惕,增加用户触发真实交易、泄露凭证或批准危险操作的概率。
UI 可直接触发 live trade,但代码中没有看到用户确认、风险警告、金额复核或防误触机制。对于真实资产交易,这会显著提高误操作、脚本滥用和社工诱导点击后直接成交的风险。
The AI prompt explicitly frames the model as a paper-trading analyzer, but its output is later used to drive real on-chain trades. This mismatch is dangerous because it lowers operator expectations and can cause unsafe reliance on model output in a financially irreversible context.
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
"bot_setting": [
{
"bot_name": "TraderBot",
"content": "You are a helpful trading assistant. Always respond with valid JSON only, no explanations."
}
],
"reply_constraints": {
The bot executes live trading orders automatically using API credentials and private-key-backed signing without any runtime confirmation, approval workflow, or explicit safety interlock. In the context of a real-money trading skill, this materially increases the chance of unintended financial loss from logic bugs, bad data, model errors, or manipulated external inputs.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp "$SKILL_DIR/status_server.py" "$WORK_DIR/status_server.py"
cp -r "$SKILL_DIR/assets/public/"* "$WORK_DIR/public/"
# 如果 .env 不存在,从 example 创建
if [ ! -f "$WORK_DIR/.env" ]; then
cp "$SKILL_DIR/references/.env.example" "$WORK_DIR/.env"
echo "⚠️ 已创建 .env,请编辑 $WORK_DIR/.env 填入 API Key!"
No suspicious patterns detected.