Back to skill

Security audit

Polymarket Micro Session Edge Trader

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is mostly transparent about its purpose, but its live-trading safety controls do not fully match what it promises.

Review before installing. Use only a low-limit or simulation-only API key unless the risk controls are fixed, pin or lock the SDK dependency, and do not rely on the documented volume, threshold, or open-position limits to cap real exposure in live mode.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Trading SDK Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:326
Finding

Declared Trading Risk Controls Are Not Enforced

Content
View full analysis
higher conviction boost # Fade trades use wider thresholds — the market near 50% IS the opportunity fade_yes_limit = 0.52 # buy YES up to 52% after down-burst fade_no_limit = 0.48 # sell NO down to 48% after up-burst if fade_side == "no": # Fading an up-burst: sell NO (bet Down) if p < fade_no_limit: return None, 0, f"NO blocked at {p:.1%}; fade limit is {fade_no_limit:.0%}" conviction = min(1.0, (p - fade_no_limit) / 0.30) burst_strength = max(0, (burst_avg_p - 0.55) / 0.45) combined = min(1.0, conviction + 0.3 * burst_strength) size = max(MIN_TRADE, round(combined * MAX_POSITION, 2)) return "no", size, reasoning if fade_side == "yes": # Fading a down-burst: buy YES (bet Up) if p > fade_yes_limit: return None, 0, f"YES blocked at {p:.1%}; fade limit is ...[truncated 3068 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:63
Finding

Global Client Cache Can Reuse Live Trading Mode During a Paper Run

Content
View full analysis
SimmerClient: global _client, MAX_POSITION, MIN_TRADE, MAX_SPREAD, MIN_DAYS global MAX_POSITIONS, YES_THRESHOLD, NO_THRESHOLD, MIN_VOLUME if _client is None: venue = "polymarket" if live else "sim" _client = SimmerClient( api_key=os.environ["SIMMER_API_KEY"], venue=venue, ) if live: _client.live = True try: _client.apply_skill_config(SKILL_SLUG) except AttributeError: pass MAX_POSITION = float(os.environ.get("SIMMER_MAX_POSITION", str(MAX_POSITION))) MIN_TRADE = float(os.environ.get("SIMMER_MIN_TRADE", str(MIN_TRADE))) MAX_SPREAD = float(os.environ.get("SIMMER_MAX_SPREAD", str(MAX_SPREAD))) MIN_DAYS = int(os.environ.get( "SIMMER_MIN_DAYS", str(MIN_DAYS))) MAX_POSITIONS = int(os.environ.get( "SIMMER_MAX_POSITIONS", str(MAX_POSITIONS))) YES_THRESHOLD = float(os.environ.get("SIMMER_YES_THRESHOLD", str(YES_THRESHOLD))) NO_THRESHOLD = float(os.environ.get("SIMMER_NO_THRESHOLD", str(NO_THRESHOLD))) MIN_VOLUME = float(os.environ.get("SIMMER_MIN_VOLUME", str(MIN_VOLUME))) return _client ``` ### Technical Analysis `_client` is a module-global singleton. Its venue and live state are selected only when the client is first created. Subsequent calls return the same object without verifying that its mode matches the newly requested `live` argument. As a result, a long-lived host process that first calls `run(live=True)` and later calls `run(live=False)` will retain the client created with: ```python venue = "polymarket" _client.live = True ``` The later invocation prints `PAPER (sim)` based on its local argument ...[truncated 1443 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes behavior that handles trading plumbing, requires a high-value API credential, and references capabilities consistent with environment access and file writing, yet it declares no explicit tool scope or permission boundaries. In an agent setting, missing scope declarations can allow broader-than-expected access to credentials or local files, increasing the blast radius if the skill is misused or composed with other automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.