Back to skill

Security audit

Polymarket Ladder F1 Championship Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed trading skill, but its live-trading authority and incompletely enforced risk controls make it something users should review carefully before installing.

Install only if you understand it can place real Polymarket orders when run with --live. Use a limited or paper-only API key if available, keep live runs manual, pin and review simmer-sdk before use, and do not rely on the documented volume or concurrent-position limits until the implementation enforces them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:73
Finding

Declared Live-Trading Exposure Controls Are Not Fully Enforced

Content
View full analysis
= MAX_POSITIONS: break if len(champ_markets) < 2: safe_print(f" [skip] {champ_name}: only {len(champ_markets)} driver(s), need >= 2") continue total_sum = sum(m.current_probability for m in champ_markets) violation = abs(total_sum - 1.0) safe_print( f" [group] {champ_name}: {len(champ_markets)} drivers, " f"sum={total_sum:.1%}, violation={violation:.1%}" ) if violation < MIN_VIOLATION: safe_print(f" [skip] {champ_name}: violation {violation:.1%} < {MIN_VIOLATION:.0%} threshold") continue is_overpriced = total_sum > 1.0 # Sort: overpriced -> highest p first; underpriced -> lowest p first if is_overpriced: champ_markets.sort(key=lambda m: m.current_probability, reverse=True) else: champ_markets.sort(key=lambda m: m.current_probability) for m in champ_markets: if placed >= MAX_POSITIONS: break ``` The trade result increments only the invocation-local counter: ```python if r.success: placed += 1 ``` `MIN_VOLUME` is loaded initially and refreshed after applying skill configuration, but it is never used to reject a market before `client.trade()` is called. ...[truncated 2623 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly requires a high-value credential (SIMMER_API_KEY) and is designed to place trades, but it does not declare a tool/permission scope limiting access to environment-derived secrets or execution capabilities. In an agent platform, missing explicit scope boundaries increases the chance the skill can access or misuse credentials beyond what operators expect, especially if later paired with executable code.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
F1 driver championship winner probabilities on Polymarket systematically deviate from a 100% total because of three structural mechanisms:

1. **Retail trades drivers individually** -- users buy YES on their favorite driver without checking whether the field total already exceeds 100%. A wave of enthusiasm after a race result inflates the winner without deflating the rest.
2. **No cross-market consistency enforcement** -- unlike a traditional bookmaker who adjusts the entire field when one runner's odds move, Polymarket has no market maker enforcing that the sum of all driver probabilities stays at 100%. Each driver is a separate order book with independent liquidity.
3. **Driver entry and exit creates transient imbalances** -- when a new driver is added to the championship market (mid-season replacement, rookie promotion) or a driver is removed (retirement, disqualification), the existing prices do not instantly re-normalize. The sum drifts until enough traders notice and correct it.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest declares a required sensitive environment variable, SIMMER_API_KEY, indicating the skill will access credentials at runtime. In this file there is no accompanying warning or disclosure explaining that the skill uses an API key, which is relevant to user privacy and account safety.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.