Back to skill

Security audit

Polymarket Esports Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading skill, but its live-trading path has a real risk-control gap and an unpinned high-privilege dependency that users should review before installing.

Install only if you are comfortable with a trading bot that can place real Polymarket orders when run with --live. Keep it in paper mode unless you have reviewed the strategy, enforce or remove the minimum-volume setting before live use, pin and review simmer-sdk, and use a tightly limited SIMMER_API_KEY with account-side spending/order limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:339
Finding

Configured Minimum-Volume Safeguard Is Not Enforced

Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" print(f" [trade] {side.upper()} ${size} {tag} {status} — {reasoning[:70]}") if r.success: placed += 1 except Exception as e: print(f" [error] {m.id}: {e}") ``` ### Technical Analysis `SIMMER_MIN_VOLUME` is loaded into `MIN_VOLUME`, exposed as a tunable, printed at runtime, and documented as a market-volume filter. However, neither `compute_signal()` nor `run()` compares a candidate market's volume against that value. Consequently, market eligibility depends on probability, spread, resolution date, and context checks, but not liquidity. This creates a fail-open condition in a financial safety control. Operators may reasonably rely on the configured minimum-volume value when enabling live trading, even though it has no effect on order placement. ### Attack Path 1. The process is launched with `--live`, enabling real Polymarket o ...[truncated 1015 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

High-Privilege Trading Dependency Is Not Version-Pinned

Content
View full analysis
Remediation
View remediation
" ] ``` 2. Use a lock file or constraints file with cryptographic hashes where the deployment platform supports it. 3. Resolve and review transitive dependencies, not only the direct package. 4. Route upgrades through explicit security review, automated testing, and controlled deployment rather than automatically accepting the latest release. 5. Install dependencies from a trusted, authenticated package repository and monitor package ownership and release changes. 6. Run the Skill under a dedicated, least-privileged operating-system account. 7. Limit the API key to only the required trading permissions and enforce server-side account, order-size, and spending limits. 8. Rotate `SIMMER_API_KEY` promptly if a dependency compromise is suspected. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly requires a high-value environment credential (SIMMER_API_KEY) but does not declare any tool scope, permissions, or allowed-tools boundary for accessing environment data. That mismatch weakens least-privilege controls and can let the runtime expose more capability than the manifest communicates, increasing the risk of unintended secret access or misuse if the skill is later extended or interpreted permissively.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.