Back to skill

Security audit

Polymarket Whale Exit Fade Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading skill, but its live-trading safeguards and dependency controls are weak enough that users should review it carefully before installing.

Install only after reviewing the code and SDK provenance. Use paper mode unless you explicitly intend real trades, provide a dedicated least-privilege API key, set account-side spending and trading limits, and do not rely on the documented volume, open-position, slippage, or flip-flop controls without fixing or independently enforcing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
clawhub.json:3
Finding

Unpinned Trading SDK Creates a Supply-Chain Compromise Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:361
Finding

Live-Trading Context Safeguards Fail Open on Errors

Content
View full analysis
tuple[bool, str]: """Check flip-flop and slippage safeguards.""" try: ctx = client.get_market_context(market_id) if not ctx: return True, "no context" if ctx.get("discipline", {}).get("is_flip_flop"): reason = ctx["discipline"].get("flip_flop_reason", "recent reversal") return False, f"Flip-flop: {reason}" slip = ctx.get("slippage", {}) if isinstance(slip, dict) and slip.get("slippage_pct", 0) > 0.15: return False, f"Slippage {slip['slippage_pct']:.1%}" for w in ctx.get("warnings", []): safe_print(f" [warn] {w}") except Exception as e: safe_print(f" [ctx] {market_id}: {e}") return True, "ok" ``` The result is subsequently trusted before order submission: ```python # Context check ok, why = context_ok(client, market.id) if not ok: safe_print(f" [skip] {why}") continue # Execute trade try: r = client.trade( market_id=market.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `context_ok()` is intended to block trades when market context reports excessive slippage or a rapid position reversal. However, every exception raised while retrieving or parsing that context is caught and converted into approval through the final `return True, "ok"`. The function also explicitly approves a missing or false-valued context with `return True, "no context"`. This means that the absence of evidence that a trade is safe is treated as evidence of safety. Because the same path is used in paper and live modes ...[truncated 1679 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
trader.py:463
Finding

Declared Liquidity and Open-Position Limits Are Not Enforced

Content
View full analysis
= MAX_POSITIONS: break # Use fade-enhanced signal side, size, reasoning = compute_fade_signal( market, fade_direction, whale_count, exit_vol ) if not side: safe_print(f" [skip] {reasoning}") continue # Context check ok, why = context_ok(client, market.id) if not ok: safe_print(f" [skip] {why}") continue # Execute trade try: r = client.trade( market_id=market.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" safe_print(f" [trade] {side.upper()} ${size} {tag} {status} -- {reasoning[:120]}") if r.success: placed += 1 ``` ### Technical Analysis `MIN_VOLUME` is loaded from the environment and documented as a minimum market-volume safeguard, but no execution path checks a candidate market's volume against it. A qualifying signal c ...[truncated 2126 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly depends on network access and an environment variable (SIMMER_API_KEY) but does not declare any tool scope or allowed-tools boundary. In an agent ecosystem, missing capability declarations weakens least-privilege controls and can let the skill run with broader access than reviewers or users expect, increasing the chance of unintended outbound requests or secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill notes that trades are simulated unless --live is passed, but it does not present a prominent, unambiguous warning that live mode can execute real-money trades. In a trading skill, that omission materially increases the risk of user misunderstanding, accidental live execution, and financial loss, especially because the strategy is designed to act on volatile whale-exit signals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest requires the environment variable SIMMER_API_KEY, which indicates the skill depends on a sensitive credential. The file provides no accompanying warning or disclosure about handling API credentials or the implications of supplying them, which is relevant user-facing safety information for a trading-related skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.