Back to skill

Security audit

Polymarket Copy Dynamic Roster Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real-money copytrading automation, and its live-trading safeguards are not fully enforced as documented.

Review this carefully before installing. Keep it in paper mode unless you have fixed or accepted the live-trading risks, use a narrowly scoped Simmer API key with account-level spending/trade limits, pin the SDK version, and require live execution to fail closed when market or portfolio safety checks cannot be verified.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:345
Finding

Advertised market safeguards are not enforced during copied trade execution

Content
View full analysis
YES_THRESHOLD: skip_reason = f"YES prob {prob:.0%} > threshold {YES_THRESHOLD:.0%}" elif side.lower() == "no" and prob < NO_THRESHOLD: skip_reason = f"NO prob {prob:.0%} < threshold {NO_THRESHOLD:.0%}" if skip_reason: safe_print(f" SKIP: {skip_reason} | {question}") skipped += 1 details.append({"action": "skip", "reason": skip_reason, "market": question}) continue # Cap amount amount = min(amount, max_usd, MAX_POSITION) if dry_run: safe_print(f" [DRY] {side.upper()} ${amount:.2f} @ {prob:.0%} | {question}") executed += 1 details.append({"action": "dry_run", "side": side, "amount": amount, "market": question}) else: try: r = client.trade( market_id=market_id, side=side, amount=amount, source=TRADE_SOURCE, ) ``` The spread and resolution safeguards are implemented separately but never called by the copy-trading execution path: ```python def compute_signal(market) -> tuple[str | None, float, str]: """Standard conviction-based signal for market validation.""" p = market.cu ...[truncated 3140 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:431
Finding

Portfolio position-limit check fails open on errors

Content
View full analysis
bool: """Check portfolio context to prevent excessive positions or flip-flops.""" try: positions = client.get_positions() open_count = len([p for p in positions if float(getattr(p, "size", 0)) > 0]) if open_count >= MAX_POSITIONS: safe_print(f" [GATE] Already at {open_count}/{MAX_POSITIONS} positions, skipping") return False except Exception as exc: safe_print(f" [WARN] Could not check positions: {exc}") return True ``` ### Technical Analysis The portfolio check is intended to prevent trading after the configured maximum number of positions has been reached. However, every exception raised by `client.get_positions()`, response parsing, attribute access, or numeric conversion is caught and converted into approval because the function ultimately returns `True`. This is a fail-open design. The inability to verify a safety precondition is treated as if the precondition passed. Authentication errors, service outages, malformed responses, SDK incompatibilities, and transient network failures can therefore disable the position-limit control. ### Attack Path 1. The Skill is started with `--live`. 2. `client.get_positions()` fails because of a network error, authentication problem, malformed response, SDK error, or upstream service failure. 3. The broad `except Exception` handler logs a warning but does not block execution. 4. `context_ok()` returns `True`. 5. Roster construction and copy-trading continue. 6. New positions may be opened even when the account is already at or above `MAX_POSITIONS`. A compromised upstream service could also deliberately return malformed position data to trigger this behavior, although ordinary operational failures are suffic ...[truncated 408 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Security-sensitive trading SDK is installed without version or integrity pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes behavior that relies on network access and environment-based secrets (SIMMER_API_KEY) but does not declare any explicit tool scope or allowed tools. That mismatch weakens reviewability and containment, making it easier for an agent runtime to grant broader access than users expect or for future revisions to expand capabilities without transparent permission boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill automates copytrading and notes that paper mode is the default, but it does not prominently and explicitly warn that enabling live mode will place real trades automatically using the user's account and API key. In a financial trading context, insufficient disclosure is dangerous because a user may switch modes or deploy the skill without fully understanding that it can execute real market actions and incur immediate monetary loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.