Back to skill

Security audit

Polymarket Btc Weekend Volatility Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed paper-by-default trading bot, but it needs Review because live mode can place real trades while some documented safeguards are missing or ineffective.

Review before installing. Keep it in paper mode unless you intentionally want live Polymarket trading, scope and rotate SIMMER_API_KEY where possible, set conservative position limits, and fix the missing market-window and volume checks before trusting live execution. Pin the SDK dependency to a reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:215
Finding

Weekend Market Constraint Is Calculated but Not Enforced

Content
View full analysis
bool: """ Return True if the question describes a BTC price threshold market with a weekend or short-horizon time window. Generalised — not hardcoded to any specific price level. """ q = question.lower() has_btc = any(w in q for w in ("bitcoin", "btc", "btcusdt")) has_price = any(w in q for w in ("above", "reach", "hit", "exceed", "trade at", "surpass", "break", "touch")) has_level = any(c in q for c in ("usdt", "usd", "$")) or any( w in q for w in ("100k", "110k", "120k", "130k", "140k", "150k", "160k", "170k", "180k", "200k", "000 usdt", "000 usd")) has_window = any(w in q for w in ("weekend", "saturday", "sunday", "this week", "any time", "at any point", "between", "window")) return has_btc and has_price and has_level ``` ### Technical Analysis The function calculates `has_window` but omits it from the final Boolean expression. Consequently, the function accepts any question containing BTC terminology, threshold language, and a recognized price representation, even when the question has no weekend or bounded-time condition. This violates the function contract and the strategy's documented assumptions. The strategy's claimed probability model concerns first-passage events during a weekend window; applying it to markets with materially different resolution periods or semantics can produce invalid signals. The broad keyword discovery process increases exposure to this defect because candidate markets are not restricted to an authoritativ ...[truncated 1400 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:338
Finding

Declared Minimum-Volume Trading Safeguard Is Never Applied

Content
View full analysis
list: """Find active markets matching strategy keywords, deduplicated.""" seen, unique = set(), [] for kw in KEYWORDS: try: for m in client.find_markets(query=kw): if m.id not in seen: seen.add(m.id) unique.append(m) except Exception as e: print(f"[search] {kw!r}: {e}") return unique def run(live: bool = False) -> None: mode = "LIVE" if live else "PAPER (sim)" entry_label, _ = _entry_window_mult() cycle_label, _ = _btc_cycle_mult() print(f"[polymarket-btc-weekend-volatility-trader] mode={mode} max_pos=${MAX_POSITION} entry={entry_label} cycle={cycle_label}") client = get_client(live=live) markets = find_markets(client) print(f"[polymarket-btc-weekend-volatility-trader] {len(markets)} candidate markets") placed = 0 for m in markets: if placed >= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` The unused safeguard is declared and reloaded elsewhere: ```python MIN_VOLUME = float(os.environ.get("SIMMER_MIN_VOLUME", "5000")) ``` ### Technical Analysis `MIN_VOLUME` is presented as a minimum market-volume filter, but neither `find_markets()`, `compute_signal()`, nor ...[truncated 1894 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:185
Finding

Terminal-Price Questions Receive the First-Passage Multiplier

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:6
Finding

Security-Critical Trading SDK Dependency Is Unpinned

Content
View full analysis
Remediation
View remediation
" ] ``` Additional supply-chain controls should include: 1. Generate and enforce a lock file with cryptographic hashes. 2. Install with hash verification, such as `pip --require-hashes`, where supported. 3. Record the reviewed package version and artifact digest in release metadata. 4. Verify package ownership, provenance, release signatures, and the official distribution source. 5. Run dependency vulnerability and provenance scans in CI. 6. Review updates before changing the pin rather than automatically resolving the latest version. 7. Isolate the runtime with least-privilege filesystem and network access. 8. Scope and rotate `SIMMER_API_KEY` where the platform supports credential restrictions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly requires the SIMMER_API_KEY credential but declares no permissions or allowed-tools scope, so an agent may be granted broader environment access than necessary. In a trading skill, this increases the chance of credential exposure or unintended use of sensitive environment variables if the runtime does not enforce least privilege.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation says 'no external API required' while later requiring a live trading credential and describing real trade execution through Simmer/Polymarket. This mismatch can mislead operators into underestimating the skill's external connectivity and financial authority, increasing the risk of unsafe deployment or accidental live trading.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.