Back to skill

Security audit

Polymarket Micro Coin Lag Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is clearly a trading bot and is not obviously malicious, but its live-trading risk controls do not fully match what it claims to enforce.

Review this carefully before installing, especially before using --live. Paper mode is the default, but live mode can spend real USDC, and the documented volume, threshold, and position safeguards should not be treated as fully reliable until fixed. Use a dedicated, least-privileged SIMMER_API_KEY and avoid exposing unrelated secrets in the same environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:316
Finding

Configured Financial Safeguards Are Not Fully Enforced

Content
View full analysis
tuple[str | None, float, str]: """ Returns (side, size, reasoning) or (None, 0, skip_reason). Conviction-based sizing per CLAUDE.md: - YES: conviction = (YES_THRESHOLD - p) / YES_THRESHOLD - NO: conviction = (p - NO_THRESHOLD) / (1 - NO_THRESHOLD) - size = max(MIN_TRADE, conviction * MAX_POSITION) """ p = getattr(market, "current_probability", None) if not isinstance(p, (int, float)): return None, 0, "missing probability" # Spread gate spread_cents = getattr(market, "spread_cents", None) if isinstance(spread_cents, (int, float)) and spread_cents / 100 > MAX_SPREAD: return None, 0, f"Spread {spread_cents/100:.1%} > {MAX_SPREAD:.1%}" # Days-to-resolution gate resolves_at = getattr(market, "resolves_at", None) if resolves_at: try: resolves = datetime.fromisoformat(resolves_at.replace("Z", "+00:00")) days = (resolves - datetime.now(timezone.utc)).days if days < MIN_DAYS: return None, 0, f"Only {days} days to resolve" except Exception: pass ...[truncated 3203 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:6
Finding

Security-Sensitive Trading Dependency Is Not Version-Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill references access to a high-value environment credential (SIMMER_API_KEY) but does not declare any explicit tool scope or permission boundaries. In agent platforms, undeclared environment access increases the chance that the skill can read sensitive secrets more broadly than intended, making accidental exposure, misuse for live trading, or credential exfiltration harder to constrain and audit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON manifest requires the SIMMER_API_KEY environment variable, which indicates the skill uses sensitive credentials and likely connects to an external service. The manifest provides no accompanying disclosure about credential handling, remote access, or trading-related effects, so users are not warned at the manifest level about this safety-relevant behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.