Back to skill

Security audit

Polymarket Coherence Arb

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed automated trading bot, but its live-trading safeguards are too weak for the financial authority it can use.

Review this carefully before installing. Keep it in dry-run or paper mode unless you are comfortable with experimental automated trading, use a minimally scoped SIMMER_API_KEY, keep MAX_TRADE_USD and DAILY_BUDGET_USD low, pin the SDK dependency, and do not enable live Polymarket trading until market-set validation and enforceable limit-price controls are improved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
discovery.py:65
Finding

Text-Only Grouping Can Misclassify Unrelated Markets as a Confirmed Set

Content
View full analysis
exclusivity confirmed. Anything else (partial set, mixed letters, advance/qualify wording) -> NOT confirmed.""" if len(legs) != COMPLETE_SET_SIZE: return False letters = {GROUP_RE.search(_norm(m.question)).group(1).upper() for m in legs if GROUP_RE.search(_norm(getattr(m, "question", "")))} return len(letters) == 1 ``` The discovery logic places every matching market into a bucket identified only by the group letter: ```python def discover_sets(client, limit=200): """Return [(label, [markets])] of confirmed mutually-exclusive sets, deduped by market id. Unconfirmed candidates are printed as alerts and excluded.""" sets = _configured_sets(client) seen = {} for q in SEARCH_QUERIES: try: for m in _fetch_markets(client, q, limit): if getattr(m, "status", "active") != "active": continue match = GROUP_RE.search(_norm(getattr(m, "question", ""))) if match: seen.setdefault(match.group(1).upper(), {})[m.id] = m except Exception as exc: # one bad query must not kill the run print(f" ! discovery query {q!r} failed: {exc}") for letter, d in sorted(seen.items()): legs = list(d.values()) if is_confirmed_set(legs): sets.append((f"Group {letter}", legs)) else: print(f" ALERT [unconfirmed-set] Group {letter}: {len(legs)} visible leg(s) — " f"exclusivity unconfirmed from text; alert only, no arb.") return sets ``` ### Technical Analysis The trading strate ...[truncated 2533 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
coherence_arb.py:81
Finding

Live Trades Are Submitted Without an Enforceable Execution-Price Bound

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:1
Finding

Unpinned SDK Dependency Runs Automatically with Trading Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares operational behavior that depends on environment variables and persistent state files, but it does not explicitly declare a tool/permission scope such as env or file write access. This weakens sandboxing and review because an agent runner may grant broader capabilities implicitly, increasing the chance of unauthorized secret access or unintended filesystem modification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.