Back to skill

Security audit

Polymarket Ai Tech Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is not obviously malicious, but it can place real Polymarket trades and its documented risk limits are not fully enforced.

Install only if you are comfortable with an automated trading script. Use paper mode first, keep SIMMER_API_KEY narrowly scoped, do not expose a live-capable key to unattended automation, and review or fix the volume and position-limit checks before using --live.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:167
Finding

Documented Minimum-Volume Safeguard Is Not Enforced

Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" print(f" [trade] {side.upper()} ${size} {tag} {status} — {reasoning[:70]}") if r.success: placed += 1 except Exception as e: print(f" [error] {m.id}: {e}") ``` ### Technical Analysis The skill loads `SIMMER_MIN_VOLUME` into `MIN_VOLUME` and describes it as a market-liquidity risk control. However, neither `compute_signal()` nor the trading loop compares a market's volume with this value. The variable is only displayed in status output. Consequently, every discovered market that passes the probability, spread, resolution-date, flip-flop, and slippage checks remains eligible for trading regardless of its actual volume. This is a fail-open implementation of a documented financial safeguard. Low-volume markets may have inadequate order-book depth even if the reported bid-ask spread appears acceptable. The spread check therefore does not replace a volume or liquidity check. ### Attack Path 1. A user provides a live-capable `SIMMER_API_K ...[truncated 1176 chars]
Remediation
View remediation
tuple[bool, str]: try: volume = float(market.volume) except (AttributeError, TypeError, ValueError): return False, "Market volume unavailable or invalid" if volume < MIN_VOLUME: return False, f"Volume ${volume:,.2f} below minimum ${MIN_VOLUME:,.2f}" return True, "ok" ``` Invoke this check before `compute_signal()` and again before a live trade if refreshed market information is available. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:136
Finding

Minimum Trade Configuration Can Bypass the Maximum Position Limit

Content
View full analysis
= NO_THRESHOLD: conviction = (p - NO_THRESHOLD) / (1 - NO_THRESHOLD) size = max(MIN_TRADE, round(conviction * MAX_POSITION, 2)) edge = p - NO_THRESHOLD return "no", size, f"NO YES={p:.0%} edge={edge:.0%} size=${size} — {q[:70]}" ``` The supported configuration ranges permit an inconsistent combination: ```json { "env": "SIMMER_MAX_POSITION", "default": 40, "range": [1, 200] }, { "env": "SIMMER_MIN_TRADE", "type": "number", "default": 5, "range": [1, 100] } ``` ### Technical Analysis The amount calculation applies a lower bound using `max(MIN_TRADE, calculated_size)` but never applies an upper bound of `MAX_POSITION`. The supported tunable ranges allow `SIMMER_MIN_TRADE` to be greater than `SIMMER_MAX_POSITION`, such as a minimum trade of `$100` and a maximum position of `$1`. For every qualifying signal under that configuration, `max()` selects the larger minimum-trade value. The order can therefore exceed the purported maximum by up to one hundred times in the demonstrated supported configuration. The code also reads these values directly from environment variables without validating their relationship. Environment-provided values are not constrained by the JSON UI ranges, so direct execution could create an even larger discrepancy. ### Attack Path 1. A user, deployment system, or party with access to skill tunables sets `SIMMER_MAX_POSITION=1`. 2. The same party sets `SIMMER_MIN_TRADE=100`, which is ...[truncated 1040 chars]
Remediation
View remediation
None: if MAX_POSITION <= 0: raise ValueError("MAX_POSITION must be positive") if MIN_TRADE <= 0: raise ValueError("MIN_TRADE must be positive") if MIN_TRADE > MAX_POSITION: raise ValueError("MIN_TRADE must not exceed MAX_POSITION") def bounded_trade_size(conviction: float) -> float: calculated = round(conviction * MAX_POSITION, 2) return min(MAX_POSITION, max(MIN_TRADE, calculated)) ``` The `clawhub.json` schema or management UI should also enforce the cross-field constraint, although server-side or runtime validation remains necessary. ]]>

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Security-Sensitive Trading SDK Dependency Is Not Version-Pinned

Content
View full analysis
Remediation
View remediation
" ] ``` The placeholder must be replaced with an actually reviewed release, and the resolved artifact should be integrity-verified. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill references environment-based credentials (SIMMER_API_KEY) and describes live-trading capability, but it does not declare an explicit tool scope or permission boundary. In an agent ecosystem, missing permissions/allowed-tools metadata can cause the runtime to grant broader access than intended or make it unclear that the skill should be allowed to read secrets, which increases the chance of unintended credential exposure or unsafe execution paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description is broad enough to match generic requests about AI, technology, or trading, which can cause the skill to be invoked outside a narrowly intended context. Because this skill concerns financial trading and can be configured for live execution, over-broad triggering raises the risk of unintended market actions, misuse of trading authority, or the agent steering users into a specialized high-risk workflow without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.