Back to skill

Security audit

Polymarket Macro Weekend Momentum Trader

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is mostly transparent and defaults to paper mode, but its live-trading safety controls do not fully match what it advertises.

Review carefully before installing for live use. Paper mode is the default, but do not run with --live unless you accept that advertised volume and concurrent-position limits are not fully enforced. Use a restricted API key, small balances, venue-side spending limits, and a pinned/verified simmer-sdk version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:390
Finding

Advertised Market Volume and Concurrent Position Limits Are Not Enforced

Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m, drift_dir, drift_mag) if not side: safe_print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: safe_print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `SIMMER_MIN_VOLUME` is documented as a minimum market-volume filter and is loaded into `MIN_VOLUME`, but no market-volume field is inspected before `client.trade()` is called. Consequently, a market can pass the spread, resolution-time, classification, weekend, and signal checks even ...[truncated 1985 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Third-Party SDK Executes with Access to a High-Value Trading Credential

Content
View full analysis
Remediation
View remediation
" ] ``` 2. Use a lockfile or installation mechanism that records and verifies cryptographic hashes for the package and all transitive dependencies. 3. Install packages only from an approved registry over authenticated TLS, and disable unapproved extra indexes to reduce dependency-confusion risk. 4. Review package provenance, maintainers, release history, and source changes before updating the pinned version. 5. Run the trader under a dedicated, unprivileged operating-system account with minimal filesystem and network access. 6. Scope `SIMMER_API_KEY` to only the required venue and operations. Apply venue-side spending, order-size, withdrawal, and balance limits wherever available. 7. Rotate the API key after suspected dependency compromise, and monitor the account for unexpected orders or authentication activity. 8. Test SDK upgrades in simulation mode before approving them for live trading. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill references a high-value environment credential (SIMMER_API_KEY) and trading functionality but does not declare any explicit tool scope or permission boundary. In an agent ecosystem, missing scope declarations can cause the skill to receive broader environment access than necessary, increasing the blast radius if the skill is modified, misused, or composed with other agent behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The monitored keyword list is broad and includes generic BTC price phrases that are likely to match unrelated market text or common discussion contexts. In this skill, overbroad discovery can cause the strategy to select incorrect markets, misclassify contracts, or execute trades on unintended instruments, creating direct financial risk rather than just a relevance issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This manifest declares a required environment variable named SIMMER_API_KEY, which indicates the skill depends on sensitive credentials. The file provides no accompanying disclosure or warning about handling API keys, despite this being a manifest-scope description of the skill's required inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.