Back to skill

Security audit

Polymarket 24h Equity Strike Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading skill, but its live financial automation relies on safeguards that the code does not fully enforce.

Review this carefully before installing. Use paper mode first, provide only a tightly limited Simmer/Polymarket credential, do not enable live automation until the liquidity filter, open-position cap, date grouping, and dependency pinning are fixed, and assume --live can commit real USDC.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:38
Finding

Declared liquidity and portfolio position safeguards are not enforced

Content
View full analysis
tuple[bool, str]: p = getattr(market, "current_probability", None) if not isinstance(p, (int, float)): return False, "missing probability" spread_cents = getattr(market, "spread_cents", None) if isinstance(spread_cents, (int, float)) and spread_cents / 100 > MAX_SPREAD: return False, f"Spread {spread_cents/100:.1%} > {MAX_SPREAD:.1%}" resolves_at = getattr(market, "resolves_at", None) if resolves_at: try: resolves = datetime.fromisoformat(resolves_at.replace("Z", "+00:00")) days = (resolves - datetime.now(timezone.utc)).days if days < MIN_DAYS: return False, f"Only {days} days to resolve" except Exception: pass return True, "ok" ``` ```python placed = 0 for market_id, opp in sorted(all_opps.items(), key=lambda x: -x[1][2]): if placed >= MAX_POSITIONS: break ``` ### Technical Analysis `SIMMER_MIN_VOLUME` is loaded as a configurable risk parameter, but `valid_market()` never checks market volume. A market can therefore pass validat ...[truncated 1699 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:117
Finding

Ambiguous weekly market grouping can produce false live-trading signals

Content
View full analysis
str | None: for pat in _DATE_PATTERNS: m = pat.search(question) if m: groups = m.groups() if groups: return groups[0].strip().lower() # "finish week" pattern has no capture group return "week" return None ``` ```python key = f"{ticker}|{date_key}" point = CurvePoint(m, ticker, date_key, threshold, float(p)) curves.setdefault(key, []).append(point) ``` ```python for curve_key, points in curves.items(): if len(points) < 2: continue violations = find_violations(points) for market, side, mag, reason in violations: mid = getattr(market, "id", None) if not mid: continue existing = all_opps.get(mid) if existing is None or mag > existing[2]: ...[truncated 1934 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Security-sensitive trading dependency is not version or integrity pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly requires an API credential and configures an automated trader entrypoint, but it provides no user-facing disclosure about credential usage or that the skill can perform external trading activity. In a trading skill, this omission is security-relevant because users may supply sensitive credentials without clear notice that the agent can access external services and place market actions on their behalf.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.