Back to skill

Security audit

Polymarket Copy Early Mover Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading bot, but live mode can place real trades and some safety and dependency controls are under-scoped.

Review this carefully before installing. Keep it in paper mode unless you intentionally want automated trading, use a minimally scoped Simmer API key, set conservative position limits, and prefer a pinned reviewed simmer-sdk version before enabling live mode.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Privileged Third-Party Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:435
Finding

Position-Limit Safety Check Fails Open

Content
View full analysis
bool: """Check portfolio context to prevent excessive positions.""" try: positions = client.get_positions() open_count = len([p for p in positions if float(getattr(p, "size", 0)) > 0]) if open_count >= MAX_POSITIONS: safe_print(f" [GATE] Already at {open_count}/{MAX_POSITIONS} positions, skipping") return False except Exception as exc: safe_print(f" [WARN] Could not check positions: {exc}") return True ``` ### Technical Analysis `context_ok()` is intended to enforce the documented `MAX_POSITIONS` portfolio limit. However, every exception raised while retrieving or parsing positions is caught, after which the function returns `True`. The control therefore treats an unknown or unverifiable portfolio state as safe. Failures can arise from network outages, authentication problems, API changes, malformed position objects, or values that cannot be converted to `float`. The broad `except Exception` also conceals programming and data-validation errors that should stop live trading. This behavior is especially significant in live mode because successful approval allows the run loop to continue to `client.trade(...)`. In addition, the check occurs only once before the trading loop. If multiple signals are executed in one run, the code does not refresh the open-position count after each trade. ### Attack Path 1. The Skill is started with `--live`, selecting the live Polymarket venue. 2. The account is already at or near `MAX_POSITIONS`. 3. `client.get_positions()` fails, or a returned position contains malformed data that causes position parsing to raise an exception. 4. The exception is logged but suppressed. 5. `context_ok()` returns `True`, even though the configured l ...[truncated 1029 chars]
Remediation
View remediation
bool: try: positions = client.get_positions() open_count = sum( 1 for position in positions if float(getattr(position, "size", 0)) > 0 ) except (TypeError, ValueError, AttributeError, OSError) as exc: safe_print(f" [GATE] Portfolio state unavailable: {exc}") return False if open_count >= MAX_POSITIONS: safe_print( f" [GATE] Already at {open_count}/{MAX_POSITIONS} positions, skipping" ) return False return True ``` 2. Treat authentication, network, parsing, and schema failures as blocking errors in live mode. 3. Avoid catching `Exception` unless the code immediately aborts trading; catch only anticipated exception classes. 4. Recheck the portfolio immediately before each live trade, or maintain and validate a local count after every successful order. 5. Use an atomic server-side position or exposure limit where supported, because a client-side preflight check can become stale. 6. Add tests proving that API errors, malformed position sizes, and unavailable portfolio data prevent all live order submission. 7. Consider allowing fail-open behavior only in paper mode, while always requiring fail-closed behavior in live mode. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes functionality that relies on environment variables and outbound network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an unnecessary trust gap: an agent or runtime may grant broader access than users expect, increasing the risk of unauthorized data exposure or unintended external requests if the skill is executed in a permissive environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill discusses executing copy trades and notes that paper mode is the default, but it does not clearly warn that enabling live trading can result in real financial loss, slippage, or poor outcomes from blindly following whale activity. In a financial trading context, the absence of an explicit live-trading risk warning makes misuse more likely and can cause users to enable real-money execution without understanding the risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The stated purpose is to follow the detected early mover's freshest entries as the core edge. However, the trade decision is not driven solely by the whale's position; it only trades when a separate conviction model based on market probability thresholds also produces a matching yes/no signal, which materially changes the strategy's behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and module docstring describe isolating the single most predictive 'lead indicator' wallet and copying that whale's fresh positions. In practice, the code ranks wallets and then pulls fresh entries from the top 3 movers, broadening behavior from one leader to multiple wallets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.