Back to skill

Security audit

Polymarket Ai Divergence

Security checks for vulnerabilities and agentic risk

Overview

This is a real-money trading skill with mostly disclosed behavior, but it has under-scoped credential handling and dry-run/account-state mismatches that deserve review before installation.

Review this carefully before installing. Use paper or managed-wallet mode where possible, avoid exposing a wallet private key to an agent process, restrict funds and API scopes, do not override SIMMER_API_URL unless you trust the endpoint, and treat the default scan command as not purely read-only until auto-redemption is explicitly gated.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/status.py:18
Finding

Bearer Credential Can Be Transmitted to an Arbitrary Endpoint

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
ai_divergence.py:1037
Finding

Documented Dry-Run Mode Invokes a Potentially State-Changing Redemption Operation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Security-Sensitive Trading SDK Uses an Unbounded Floating Version

Content
View full analysis
=0.11.1" label: "Install Simmer SDK (uv)" ``` ```bash python -m pip install "simmer-sdk>=0.11.1" ``` `clawhub.json`: ```json "pip": [ "simmer-sdk>=0.11.1" ] ``` ### Technical Analysis The dependency specification accepts version `0.11.1` and every later release. It does not include: - An exact audited version - An upper version boundary - Package integrity hashes - A lockfile - Provenance or signature verification This is especially significant because the SDK is entrusted with the `SIMMER_API_KEY`, may access `WALLET_PRIVATE_KEY`, performs authenticated requests, signs orders, obtains balances and positions, redeems positions, and executes trades. A future release matching `>=0.11.1` can therefore acquire the same sensitive capabilities without the Skill package itself changing or undergoing another audit. Dependency repository compromise, maintainer compromise, malicious release publication, or an unintended breaking release could all alter the effective security behavior. No evidence was found that the currently referenced package is malicious. The vulnerability is the non-reproducible and overly broad dependency trust policy applied to a component with financial and credential privileges. ### Attack Path 1. An attacker compromises the package publisher account or dependency distribution infrastructure, or publishes a malicious later release through another supply-chain compromise. 2. The malicious release has a version greater than or equal to `0.11.1`. 3. A new installation or upgrade executes: ```bash python -m pip install "simmer-sdk>=0.11.1" ``` 4. The package resolver selects the malicious or compromised later version. ...[truncated 973 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tainted flow: 'req' from os.environ.get (line 30, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/status.py (reported line 34)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/markets",
            headers={"Authorization": f"Bearer {api_key}"}
        )
        data = json.loads(urlopen(req, timeout=30).read())
        markets = data.get("markets", [])
        
        high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an end-to-end market-scanning and trading skill, but the supplied code is only a data access layer for Polymarket's public Gamma API. It supports searching events, listing/getting markets and events, and parsing returned JSON into normalized structures with fields like prices, liquidity, and volume. There is no logic for comparing AI consensus to market prices, no edge calculation, no shrinkage/calibration model, no Kelly sizing, no filtering based on spreads or time-to-resolution, and no order placement or trading. While the parsed data could support such a strategy in a larger system, this chunk itself materially differs in primary purpose and capabilities from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full divergence-trading skill: identify mispriced markets, shrink edge estimates, filter by safeguards, and execute trades. The supplied code chunk only performs a read-only status check against the markets API and prints aggregate divergence counts plus a top opportunity. While the code is related to the scanning aspect of the description, it omits the core advertised behaviors—risk-adjusted sizing, safeguard checks, and order execution. That is a material difference in primary purpose/capability, so this chunk does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network and environment-dependent behavior but does not define an explicit tool scope such as permissions or allowed-tools. In an agent environment, that ambiguity can let the runtime expose broader capabilities than users expect, increasing the chance of unintended API calls, credential access, or autonomous trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to provide a wallet private key and store it in an environment variable, but it does not include strong security guidance, safer alternatives, or handling constraints for this highly sensitive credential. In the context of an agentic trading skill with network access and potential trade execution, encouraging direct private-key exposure materially raises the risk of credential theft and irreversible asset loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The comment explicitly states behavior tailored to a specific execution environment, and the script's user-facing strings are hard-coded in English throughout with no mechanism for locale selection or user opt-in. Under the policy rule, forcing a specific language without offering choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata states it will execute trades only on zero-fee markets, but the implementation explicitly permits trading on markets with nonzero fees whenever the residual edge remains above the configured threshold. This is a specification/behavior mismatch that can cause operators to trade in conditions they believed were excluded, increasing financial risk and undermining informed consent about strategy constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly invites use of a WALLET_PRIVATE_KEY for self-custody trading but does not present an explicit warning about the risks of live trading, irreversible financial loss, or the sensitivity of private-key handling. In this skill’s context, the danger is heightened because the skill is designed to place automated real-money trades, so users may expose a signing key without clear notice of operational and custody risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description presents the behavior as scanning for divergence and placing trades, but on startup the code also calls auto_redeem() and suppresses any exception. This introduces undeclared account-affecting behavior, which is risky in a trading skill because it changes wallet state and may trigger unexpected settlement actions outside the user’s expected workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code file performs outbound HTTP requests to a third-party API and includes user-provided values in request URLs, such as search queries and event slugs. While the module docstring explains that it uses Polymarket's Gamma API, it does not clearly warn users that their inputs will be transmitted over the network to that external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.