Back to skill

Security audit

Polymarket Onlyfans Trader

Security checks for vulnerabilities and agentic risk

Overview

This real-money trading skill is mostly transparent, but it needs review because some advertised trading safeguards and market scoping do not actually constrain live trades.

Install only if you are comfortable giving this skill trading authority. Keep it in paper mode until you have reviewed the strategy, pin or vet the SDK, and do not use --live unless you accept that low-volume markets, repeated runs, and generic OnlyFans markets may still create real USDC exposure beyond the advertised safeguards.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:452
Finding

Declared Minimum Market Volume Safeguard Is Not Enforced

Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis The application loads `SIMMER_MIN_VOLUME` and documents it as a minimum market-volume safety control. However, neither `compute_signal` nor the order-submission loop checks a market's volume against `MIN_VOLUME`. The implemented pre-trade controls only cover the spread, time until resolution, flip-flop detection, and reported slippage. Consequently, a market that satisfies those checks can be traded even if it has negligible liquidity. This is a fail-open financial risk-control defect. The existence of the configuration option may also cause operators to believe that low-volume markets are being rejected when the value has no effect. ### Attack Path 1. An attacker creates, promotes, or identifies a low-volume market whose question matches one of the broad OnlyFans search keywords. 2. The operator starts the skill with the `--live` option. 3. `find_markets` returns the low-volume market. 4. The market probability falls outside one of the configured YES or NO thresholds, causing `comput ...[truncated 822 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:457
Finding

Configured Maximum Open Position Limit Only Restricts Orders Per Run

Content
View full analysis
= MAX_POSITIONS: break side, size, reasoning = compute_signal(m) if not side: print(f" [skip] {reasoning}") continue ok, why = context_ok(client, m.id) if not ok: print(f" [skip] {why}") continue try: r = client.trade( market_id=m.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" print(f" [trade] {side.upper()} ${size} {tag} {status} — {reasoning[:75]}") if r.success: placed += 1 ``` The corresponding configuration describes the value as a maximum number of open positions: ```json { "env": "SIMMER_MAX_POSITIONS", "type": "number", "default": 8, "range": [ 1, 20 ], "step": 1, "label": "Max open positions" } ``` ### Technical Analysis The local `placed` counter starts at zero every time the process runs. It counts successful orders submitted during the current invocation, not the account's existing open positions. The code never queries the trading account for current positions and does not check whether a position already exists in a candidate market. Therefore, the implementation does not enforce the control represented by the label “Max open positions.” This defect is especially relevant when the script is invoked repeatedly, manually, or by an external scheduler. Each invocation receives a new order allowance regardless of the account's existing exposure. ### Attack Path 1. The trading account already has open positions, potentially in ...[truncated 1144 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Privileged Trading SDK Dependency Is Not Version-Pinned

Content
View full analysis
Remediation
View remediation
" ] ``` 2. Use a lock file or hash-validated requirements file, for example: ```text simmer-sdk== --hash=sha256: ``` 3. Verify hashes for all transitive dependencies, not only the direct SDK package. 4. Review dependency changes before upgrades and use automated vulnerability and provenance scanning. 5. Prefer trusted package indexes and disable fallback to untrusted or unexpected indexes. 6. Restrict `SIMMER_API_KEY` with server-side least privilege, maximum order size, portfolio exposure, and withdrawal prohibitions where available. 7. Rotate the API key if a dependency compromise is suspected. 8. Run the skill in a sandbox with limited filesystem access, restricted outbound networking, and no unrelated credentials in its environment. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill references an environment credential (SIMMER_API_KEY) and describes trade execution, but it does not declare any explicit tool scope or allowed-tools boundary. In practice, missing capability declarations can let an agent access environment-backed secrets or execution paths more broadly than intended, which is risky for a trading skill handling high-value credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including the standalone keyword onlyfans in the trigger list is overly broad and can activate the skill on generic mentions unrelated to trading opportunities. For a skill that can eventually place trades, unintended activation increases the chance of irrelevant analysis, noisy market discovery, or accidental downstream execution in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest declares an API key requirement for an automated trading skill, but the file presents no visible warning, consent language, or safety guardrails around credential use and real-money trading behavior. In this context, the skill is explicitly designed to place trades automatically, so silent credential collection and unattended execution increase the risk of users authorizing financial actions without understanding exposure, limits, or account impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.