Back to skill

Security audit

Polymarket Whale Scanner Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed prediction-market trading skill, but its live-trading safeguards and market matching are weak enough that users should review it carefully before use.

Use this in paper mode unless you have audited it. Before enabling `--live` or scheduling it, require exact market identity matching, enforce volume and account-wide position limits, pin and review `simmer-sdk`, and use a dedicated revocable API key with strict spend and no-withdrawal limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:354
Finding

Advertised liquidity and concurrent-position safeguards are not enforced

Content
View full analysis
= MAX_POSITIONS: break ``` Orders are then submitted without checking market volume or existing account positions: ```python try: r = client.trade( market_id=matched_market.id, side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=whale_reasoning, ) tag = "(sim)" if r.simulated else "(live)" status = "OK" if r.success else f"FAIL:{r.error}" safe_print(f" [trade] {side.upper()} ${size} {tag} {status} -- {whale_reasoning[:120]}") if r.success: placed += 1 except Exception as e: safe_print(f" [error] {matched_market.id}: {e}") ``` ### Technical Analysis `MIN_VOLUME` is initialized and refreshed from configuration, but it is never used to reject illiquid markets. This conflicts with the documented minimum market-volume safeguard. Likewise, `MAX_POSITIONS` does not represent the number of concurrent open positions. It only limits success ...[truncated 1548 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trader.py:376
Finding

Ambiguous title-based matching can cause trades in the wrong market

Content
View full analysis
3] if not consensus_words: continue matches = sum(1 for w in consensus_words if w in q_lower) if matches >= max(2, len(consensus_words) // 2): matched_market = mlist[0] break ``` The upstream consensus key is also derived from a truncated title at `trader.py:149`: ```python key = title[:60] ``` ### Technical Analysis The Skill maps externally supplied activity titles to tradable Simmer markets using loose substring matching. The algorithm: - Treats words longer than three characters as identifying terms. - Uses substring rather than token or identifier equality. - Accepts a match when only two words, or approximately half the words, overlap. - Selects the first matching question encountered. - Selects the first market in the matched question's list. - Does not validate canonical event identifiers, outcome identity, resolution criteria, or resolution date. - Truncates source titles to 60 characters before consensus matching. Common terms can occur in multiple prediction markets, especially for elections, sports, cryptocurrency, or related events. Truncation can remove dates, jurisdictions, candidates, conditions, or other distinguishing details. A semantically unrelated market can consequently satisfy the overlap threshold. Because this selected object is subsequently passed to `client.trade()`, a false match can become a real-money order when live mode is enabled. ### Attack Path 1. The remote wallet-activity API returns a title containing words shared by several markets. ...[truncated 1238 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned third-party dependency receives API credentials and trading authority

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents network access to third-party endpoints and use of a sensitive environment credential (SIMMER_API_KEY), but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent-execution environment, this creates an overbroad trust boundary where the runtime may permit more capability than intended, increasing the risk of unintended outbound requests, data exposure, or misuse of live trading authority if the skill is modified or interpreted loosely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest declares a required environment variable, SIMMER_API_KEY, indicating the skill depends on sensitive credentials. The file provides no accompanying warning or disclosure that the skill will access API credentials, which is a safety-relevant behavior for users configuring the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.