Back to skill

Security audit

Polymarket Candle Engulfing Reversal Trader

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is mostly transparent and paper-trading by default, but its live-trading safeguards do not fully enforce the limits it advertises.

Install only if you are comfortable giving this skill a Simmer/Polymarket trading key. Keep it in paper mode unless you have reviewed the strategy and limits, use the smallest practical API permissions and balances, pin or review the SDK version, and do not rely on the documented volume and position limits as complete live-trading safeguards.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:23
Finding

Declared Trading Risk Controls Are Not Fully Enforced

Content
View full analysis
= MAX_POSITIONS: break ``` ### Technical Analysis Several configuration values are documented as trading safeguards but are not enforced according to their declared semantics: 1. `MIN_VOLUME` is read from the environment but never checked against a market's volume before an order is submitted. This permits orders in markets below the configured liquidity threshold. 2. `detect_engulfing` assumes that adjacent entries after sorting are consecutive five-minute intervals. It does not verify that the previous interval ends when the current one starts or that the current interval ends when the target interval starts. Missing intervals can therefore create a false engulfing signal. 3. Position size is computed with `max(MIN_TRADE, calculated_size)`. If `MIN_TRADE` is configured above `MA ...[truncated 1930 chars]
Remediation
View remediation
MAX_POSITION: raise ValueError("SIMMER_MIN_TRADE must not exceed SIMMER_MAX_POSITION") ``` 4. Enforce an absolute upper bound when calculating every order: ```python size = min(MAX_POSITION, max(MIN_TRADE, round(conviction * MAX_POSITION, 2))) ``` 5. Query the account's current open positions before placing an order. Calculate remaining capacity using existing positions plus orders placed during the current run. 6. Recheck volume, spread, position count, and market identity immediately before calling `client.trade` to reduce time-of-check/time-of-use inconsistencies. 7. Add tests covering missing intervals, low-volume markets, repeated executions, contradictory tunables, and boundary position sizes. ]]>

T08 · Insecure Dependencies

Note
Location
clawhub.json:7
Finding

Unpinned Third-Party Trading SDK Dependency

Content
View full analysis
Remediation
View remediation
" ] ``` 2. Use a lock file with cryptographic hashes where the deployment platform supports it. 3. Retrieve packages only from an explicitly configured trusted package index. 4. Review release notes and source changes before updating the pinned version. 5. Run the trading process with least privilege and expose only the environment variables and filesystem paths it requires. 6. Restrict the API key to the minimum available permissions and rotate it if dependency compromise is suspected. 7. Add dependency vulnerability and provenance checks to the release process. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill references a high-value credential (SIMMER_API_KEY) and explicitly relies on environment-provided secrets, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege controls and makes it harder for a host platform to constrain or review what secret and runtime capabilities the skill actually needs before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest requires a SIMMER_API_KEY for an external service but does not disclose that the skill depends on external network access or how the credential will be used. This creates a trust and transparency issue: users may supply a sensitive key without clear notice, increasing the risk of unintended credential exposure or misuse in downstream code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.