T09 · Insecure Skill Coding Practices
- Location
scripts/status.py:18- Finding
Bearer Credential Can Be Transmitted to an Arbitrary Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real-money trading skill with mostly disclosed behavior, but it has under-scoped credential handling and dry-run/account-state mismatches that deserve review before installation.
Review this carefully before installing. Use paper or managed-wallet mode where possible, avoid exposing a wallet private key to an agent process, restrict funds and API scopes, do not override SIMMER_API_URL unless you trust the endpoint, and treat the default scan command as not purely read-only until auto-redemption is explicitly gated.
scripts/status.py:18Bearer Credential Can Be Transmitted to an Arbitrary Endpoint
ai_divergence.py:1037Documented Dry-Run Mode Invokes a Potentially State-Changing Redemption Operation
SKILL.md:18Security-Sensitive Trading SDK Uses an Unbounded Floating Version
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
f"{SIMMER_API_URL}/api/sdk/markets",
headers={"Authorization": f"Bearer {api_key}"}
)
data = json.loads(urlopen(req, timeout=30).read())
markets = data.get("markets", [])
high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]
The declared description presents an end-to-end market-scanning and trading skill, but the supplied code is only a data access layer for Polymarket's public Gamma API. It supports searching events, listing/getting markets and events, and parsing returned JSON into normalized structures with fields like prices, liquidity, and volume. There is no logic for comparing AI consensus to market prices, no edge calculation, no shrinkage/calibration model, no Kelly sizing, no filtering based on spreads or time-to-resolution, and no order placement or trading. While the parsed data could support such a strategy in a larger system, this chunk itself materially differs in primary purpose and capabilities from the declared description.
The declared description presents a full divergence-trading skill: identify mispriced markets, shrink edge estimates, filter by safeguards, and execute trades. The supplied code chunk only performs a read-only status check against the markets API and prints aggregate divergence counts plus a top opportunity. While the code is related to the scanning aspect of the description, it omits the core advertised behaviors—risk-adjusted sizing, safeguard checks, and order execution. That is a material difference in primary purpose/capability, so this chunk does not accurately represent the declared description.
The skill declares network and environment-dependent behavior but does not define an explicit tool scope such as permissions or allowed-tools. In an agent environment, that ambiguity can let the runtime expose broader capabilities than users expect, increasing the chance of unintended API calls, credential access, or autonomous trading actions.
The skill instructs users to provide a wallet private key and store it in an environment variable, but it does not include strong security guidance, safer alternatives, or handling constraints for this highly sensitive credential. In the context of an agentic trading skill with network access and potential trade execution, encouraging direct private-key exposure materially raises the risk of credential theft and irreversible asset loss.
The comment explicitly states behavior tailored to a specific execution environment, and the script's user-facing strings are hard-coded in English throughout with no mechanism for locale selection or user opt-in. Under the policy rule, forcing a specific language without offering choice is a natural-language policy concern.
The skill metadata states it will execute trades only on zero-fee markets, but the implementation explicitly permits trading on markets with nonzero fees whenever the residual edge remains above the configured threshold. This is a specification/behavior mismatch that can cause operators to trade in conditions they believed were excluded, increasing financial risk and undermining informed consent about strategy constraints.
The manifest explicitly invites use of a WALLET_PRIVATE_KEY for self-custody trading but does not present an explicit warning about the risks of live trading, irreversible financial loss, or the sensitivity of private-key handling. In this skill’s context, the danger is heightened because the skill is designed to place automated real-money trades, so users may expose a signing key without clear notice of operational and custody risk.
The skill description presents the behavior as scanning for divergence and placing trades, but on startup the code also calls auto_redeem() and suppresses any exception. This introduces undeclared account-affecting behavior, which is risky in a trading skill because it changes wallet state and may trigger unexpected settlement actions outside the user’s expected workflow.
This code file performs outbound HTTP requests to a third-party API and includes user-provided values in request URLs, such as search queries and event slugs. While the module docstring explains that it uses Polymarket's Gamma API, it does not clearly warn users that their inputs will be transmitted over the network to that external service.
No suspicious patterns detected.