Back to skill

Security audit

Polymarket Value Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent trading skill, but it needs Review because it can use credentials for real-money trades, order cancellations, and recurring monitoring without strong user controls.

Review before installing. Use paper-trading mode by default, use a least-privilege or read-only API key where possible, do not print or store the API key in plaintext, and require explicit confirmation for every live trade, venue switch, redemption, or order cancellation. Do not add the heartbeat workflow unless you intentionally want recurring authenticated monitoring and know how to remove it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:162
Finding

Persistent Scheduled Market Monitoring Through Agent Heartbeat

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 162–180
Vulnerability Type: Cross-session scheduled activity
Risk Level: Critical

Vulnerable Code

markdown
## Heartbeat Integration

Add to `HEARTBEAT.md` for periodic market monitoring:

```markdown
## Simmer Trading (2-3x per day)
- Call GET /api/sdk/briefing?since=<lastSimmerCheck>
- Handle risk_alerts first (stop-loss, expiring positions)
- Check actions for each active venue
- Scan opportunities.new_markets for edges > 10%
- Update lastSimmerCheck in heartbeat-state.json

Track last check in memory/heartbeat-state.json:

json
{
  "lastChecks": {
    "simmer": 1712620800
  }
}
text

### Technical Analysis

The skill directs the agent to modify `HEARTBEAT.md` and `memory/heartbeat-state.json`, establishing recurring behavior that survives the current skill invocation. The installed heartbeat contacts an external API two or three times per day and processes account-related alerts and actions.

This is persistence rather than ordinary in-session configuration because the instructions are written to files used for future agent runs. The phrase “Handle risk_alerts first” may also cause future sessions to perform financial-account operations without obtaining fresh, action-specific user authorization.

The state timestamp itself is not an attacker-controlled rule and therefore does not independently establish memory poisoning. The primary issue is installation of a recurring cross-session task.

### Attack Path

1. A user invokes the trading skill for an otherwise limited market-analysis or portfolio task.
2. The agent follows the heartbeat integration instructions and adds the supplied block to `HEARTBEAT.md`.
3. The agent creates or updates `memory/heartbeat-state.json`.
4. Future heartbeat runs activate the workflow two or three times per day, even after the original interaction has ended.
5. Each run makes an authenticated request to the external Simmer API an
...[truncated 818 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that automatically add trading behavior to HEARTBEAT.md or other cross-session configuration.
  2. Require explicit, informed user consent before creating any recurring monitoring task. The confirmation should identify:
    • The execution frequency.
    • The external destination.
    • The credential that will be used.
    • The information accessed.
    • Whether any financial actions are permitted.
  3. Make recurring monitoring read-only by default. Do not allow heartbeat executions to place trades, cancel orders, redeem positions, or otherwise mutate an account.
  4. Require fresh, action-specific confirmation before every real-money operation.
  5. Provide an explicit removal procedure that deletes the heartbeat entry and related state.
  6. Restrict the API key used by scheduled monitoring to read-only permissions where supported.
  7. Keep simulated and real-money venues in separately authorized workflows. Never infer permission to use polymarket from permission to monitor or trade on sim.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:184
Finding

API Credential Disclosure Through Terminal Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 184
Vulnerability Type: Plaintext sensitive-data exposure
Risk Level: Medium

Vulnerable Code

markdown
1. Confirm API key is set: `echo $SIMMER_API_KEY`

Technical Analysis

The command does not merely test whether SIMMER_API_KEY exists. It expands and prints the complete credential to standard output. Agent transcripts, shell history integrations, terminal recordings, CI logs, screenshots, observability platforms, and support bundles may retain that output.

Although the skill correctly advises users not to hardcode the key, printing it defeats output confidentiality. An attacker who can read any resulting transcript or log can recover the bearer credential without accessing the protected environment variable directly.

Attack Path

  1. The Simmer API key is stored in the agent or workspace environment.
  2. The agent follows the getting-started instruction and executes echo $SIMMER_API_KEY.
  3. The shell expands the variable and emits the full key to terminal output.
  4. The output is captured in an agent transcript, execution log, terminal recording, screenshot, or monitoring system.
  5. A party with access to that retained output extracts the key.
  6. The party submits authenticated requests to the Simmer API using the exposed bearer credential.

Impact Assessment

The attacker obtains the privileges granted to SIMMER_API_KEY. Based on the documented API operations, those privileges may expose agent status, briefings, balances, positions, and market-account context, and may permit trades or order cancellation.

The financial impact depends on the server-side scope of the key and configured venue. Exposure could affect simulated assets, while a key authorized for Polymarket operations could potentially expose real-USDC trading capabilities. Credential compromise persists until the key is revoked or rotated.

Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a presence check that never reveals the value:

bash
if [ -n "${SIMMER_API_KEY:-}" ]; then
  echo "SIMMER_API_KEY is set"
else
  echo "SIMMER_API_KEY is not set"
fi

Additional hardening measures:

  1. Never include API-key values in terminal output, logs, exceptions, prompts, or agent responses.
  2. Apply secret redaction to execution transcripts and observability pipelines.
  3. Use least-privilege API keys, separating read-only monitoring credentials from trading credentials where supported.
  4. Rotate the key immediately if the vulnerable command has previously been executed in a logged environment.
  5. Require explicit confirmation before using a credential capable of real-money trading.
  6. Document secure revocation and rotation procedures for exposed credentials.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports switching from paper trading to real-money Polymarket trading and includes destructive order-cancellation flows, but it does not require explicit confirmation, risk disclosure, or a human approval gate before executing those actions. In the context of a trading skill, this materially increases the chance of unauthorized or accidental financial transactions and irreversible order management.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description is broad enough to trigger on common requests like checking positions or trading predictions without tightly scoping venue, risk level, or whether real-money trading is intended. In an agent environment, over-broad activation can cause the skill to engage unexpectedly and steer the agent into financial actions the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

Call this at the start of any trading session to get a full picture:

bash
curl "https://api.simmer.markets/api/sdk/briefing?since=<last_check_unix_timestamp>" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This endpoint performs an authenticated trade execution against an external trading API and can switch to a real-money venue, yet the skill provides no built-in requirement for explicit user approval at execution time. In context, this is more dangerous than read-only API usage because it enables direct financial action and potential loss if triggered incorrectly, implicitly, or by an over-broad activation.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

4. Execute a Trade

bash
curl -X POST "https://api.simmer.markets/api/sdk/trade" \
  -H "Authorization: Bearer $SIMMER_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This authenticated DELETE request can cancel a specific order, a destructive action that may materially affect trading outcomes and, on a real-money venue, financial positions. Because the skill lacks explicit confirmation and approval guidance for destructive actions, accidental or unauthorized invocation could cause direct monetary harm or interfere with user strategy.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

bash
# Cancel a specific order
curl -X DELETE "https://api.simmer.markets/api/sdk/orders/{order_id}" \
  -H "Authorization: Bearer $SIMMER_API_KEY"

# Cancel all orders on a market

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Bulk cancellation of all orders on a market is especially dangerous because a single request can unwind multiple pending actions at once, potentially disrupting hedges or execution plans and causing financial loss. In this trading context, the absence of explicit confirmation or safeguards makes the operation materially risky, particularly if real-money trading is enabled.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

-H "Authorization: Bearer $SIMMER_API_KEY"

Cancel all orders on a market

curl -X DELETE "https://api.simmer.markets/api/sdk/orders?market_id={market_id}"
-H "Authorization: Bearer $SIMMER_API_KEY"

text

Static analysis

No suspicious patterns detected.