T09 · Insecure Skill Coding Practices
- Location
trader.py:166- Finding
Incorrect trade-side normalization can generate false real-money signals
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed paper-by-default Polymarket trading skill, but live mode can place real-money trades while some documented safeguards are missing or flawed.
Review carefully before enabling live mode. Keep it in paper mode until trade-direction parsing and advertised safeguards are fixed, pin and verify the SDK dependency, and scope SIMMER_API_KEY to limited trading permissions and account exposure.
trader.py:166Incorrect trade-side normalization can generate false real-money signals
trader.py:42Documented liquidity and portfolio exposure safeguards are not enforced
clawhub.json:3Security-sensitive SDK dependency is unpinned
The skill describes behavior that relies on network access and an environment secret (SIMMER_API_KEY), but it does not declare any explicit tool scope such as allowed tools or permissions. This creates a least-privilege and transparency gap: a runner or reviewer cannot easily tell what external access the skill expects, increasing the risk of unintended network use or secret exposure if the skill is later implemented or executed in a broader-permission environment.
No suspicious patterns detected.