Back to skill

Security audit

Polymarket Copytrading

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Polymarket copytrading skill, but it is configured for recurring live trading and has control gaps that could place unintended orders.

Review this before installing in any account with real funds. Prefer dry-run first, remove or disable the managed --live schedule unless you explicitly want recurring live trades, use strict Simmer account limits, pin the SDK dependency, and verify wallet and market handling before granting an API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Trading SDK Creates a Privileged Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
copytrading.py:278
Finding

Fuzzy Search Fallback Can Resolve a Signal to the Wrong Market

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
copytrading.py:232
Finding

Trade Action Is Incorrectly Interpreted as Outcome Selection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
copytrading.py:140
Finding

Trading Safeguards Fail Open When Context Retrieval Fails

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
clawhub.json:6
Finding

Managed Deployment Automatically Enables Recurring Live Trading

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing --live immediately enables real trading without any secondary confirmation, acknowledgement prompt, or other execution guard. For a financial trading skill, this is dangerous because accidental invocation, automation misconfiguration, or command injection into a wrapper workflow can cause irreversible real-money trades with no human checkpoint.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares capabilities that imply access to environment variables and network resources, but it does not define any explicit tool scope or permission boundaries. In a skill that can place or simulate trades and uses an API key, missing scope declarations increases the risk of over-privileged execution, unintended data exposure, or unauthorized external requests if the runtime grants broad defaults.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation description is broad enough to match generic trading-related requests like 'follow smart money' or 'automate position copying,' which can cause the skill to activate in contexts where the user did not clearly intend live or semi-automated trading. In this skill, accidental invocation is more dangerous because the documented usage includes a live trading mode and automated copying of third-party wallet activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes automatic mirroring of whale wallet trades without prominently warning that third-party wallet activity may be stale, misleading, manipulative, or unsuitable for the user's risk tolerance. Because the skill supports --live execution and frames copying as a strategy with built-in safeguards, users may underestimate financial and operational risk and enable real trading without sufficient review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill can call client.import_market() on a Polymarket URL derived from external API data, which expands the set of tradable markets beyond a pre-approved local allowlist of mirrored instruments. In a copytrading skill, this increases risk because an observed whale trade can cause the bot to onboard and trade a market the operator never explicitly reviewed, reducing control over venue exposure and market quality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.