Back to skill

Security audit

Polymarket Brain

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed news-to-Discord market-analysis workflow, but it ships live Discord webhooks and can send local analysis to a fixed external channel without clear user control.

Review before installing or running. Revoke and replace the bundled Discord webhooks, configure your own destination through environment variables or a secret manager, use a dry-run/content preview first, and avoid clearing history in production. Treat any Discord output as financial commentary, not trade execution or financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
polymarket_brain_orchestrator.py:29
Finding

Live Discord Webhook Credentials Committed Across Source, Configuration, Documentation, and Tests

Content
View full analysis
" PHASE4_DISCORD_WEBHOOK = "https://discord.com/api/webhooks/1483478506070474922/" ``` The same analysis webhook is also used as an executable default: ```python webhook_url = sys.argv[1] if len(sys.argv) > 1 else "https://discord.com/api/webhooks/1483478506070474922/" ``` The tokens are redacted in this report to avoid further disclosure. Complete, apparently live values are present in the identified project files. ### Technical Analysis A Discord webhook URL contains both an identifier and a secret token. Possession of the complete URL authorizes message submission without a separate login, making it a bearer credential. The project embeds two complete webhook credentials directly in executable scripts and duplicates one of them in configuration files, documentation, snapshots, and network-executing tests. This contradicts the project's own security guidance in `SKILL.md:356-361`, which states that webhook URLs should not be committed and should instead be obtained from environment variables. Several test scripts perform real network requests against these credentials rather than using an HTTP mock. Consequently, simply running a test can modify a production Discord channel. Duplication across many files also makes reliable rotation and removal difficult. ...[truncated 1475 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/orchestrate.py:22
Finding

Task Memory Content Can Be Automatically Disclosed to a Hardcoded External Discord Destination

Content
View full analysis
" ``` It reads expert Agent output from a dated memory file: ```python def run_agent(agent_name, url, framework): """Phase 3: Execute assigned Agent""" log_status("Phase 3", f"Running {agent_name} with framework: {framework}") today = datetime.now().strftime("%Y-%m-%d") memory_file = MEMORY_DIR / f"{today}-{agent_name}.md" if not memory_file.exists(): log_status("Phase 3", f"Warning: No memory file found for {agent_name}") return { 'conclusion': 'Analysis pending', 'probability': 50, 'framework': framework } with open(memory_file, 'r', encoding='utf-8') as f: content = f.read() prob_match = re.search(r'(\d+)%', content) probability = int(prob_match.group(1)) if prob_match else 50 conclusion_match = re.search(r'## Analysis\n(.+?)(?=##|\Z)', content, re.DOTALL) conclusion = conclusion_match.group(1).strip()[:200] if conclusion_match else 'Analysis complete' return { 'conclusion': conclusion, 'probability': probability, 'framework': framework } ``` The extracted conclusion is incorporated into a Discord message and transmitted: ```python if agent_name == 'geopolitics-expert': geo_logic = f"{expert_data['framework']} suggests {expert_data['probability']}% prob ...[truncated 3339 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:192
Finding

Unpinned Third-Party Dependencies Installed from Mutable Package Index Releases

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (143)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
97% confidence
Finding

The file combines credential-like webhook references with repeated instructions and code paths for posting content externally to Discord, which strongly matches a credential/exfiltration risk pattern. Although the apparent purpose is workflow notification rather than overt theft, exposed webhook endpoints plus automated outbound posting materially increase the chance of unauthorized data exfiltration and channel abuse.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

`

python
# Execution
cd cnbc-geopolitics-fetcher
python scripts/fetch_cnbc_geopolitics.py --config references/config.md --count 5

Behavior:

  • Fetches exactly 5 articles from CNBC World Politics RSS
  • Deduplicates against references/sent_urls.txt history
  • Posts NEW articles individually to Discord (not batched)
  • Exit code 0 always (even when no new articles)

Webhook: https://discord.com/api/webhooks/1482043765471445333/...

History Management:

  • Tracks all sent URLs in sent_urls.txt
  • Skips duplicates forever
  • Growth = fewer posts over time (expected, not broken)

No New Articles Behavior:

  • Does NOT post to Discord
  • Returns exit code 0
  • Orchestrator skips Phases 2-4 (no analysis, no market matching, no Discord posts)
  • Prints console notification only (not sent to Discord)
  • Clean exit with clear status message

Phase 2: Expert Analysis

Classification Logic:

| News Content | Classification | Expert Skill | |--------------|----

Tainted flow: 'req' from os.environ.get (line 246, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 257)May include surrounding context.

python
)
    
    try:
        urllib.request.urlopen(req)
        print("  ✓ Header sent")
        time.sleep(1.2)
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 246, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 289)May include surrounding context.

python
)
    
    try:
        urllib.request.urlopen(req)
        print("  ✓ Header sent")
        time.sleep(1.2)
    except urllib.error.HTTPError as e:

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
97% confidence
Finding

This rule is triggered by a high-risk combination: access to local environment-derived BrowserOS storage paths plus a hardcoded external Discord webhook for outbound posting. Even though the current code does not explicitly harvest credentials, it accesses local memory/session-related directories and exfiltrates derived content externally, which is highly suspicious in an agent skill and could readily be adapted to leak secrets or sensitive workspace data.

Content

Scanner excerpt · scripts/orchestrate.py (reported line 22)May include surrounding context.

python
expert
3. Phase 3: Execute assigned Agent, extract Conclusion/Probability/Framework
4. Phase 4: Search Polymarket markets matching keywords
5. Phase 5: Send each market individually to Discord webhook
"""

import os
import sys
import re
import json
import requests
from datetime import datetime, timedelta
from pathlib import Path

# Configuration
SKILL_DIR = Path(__file__).parent
MEMORY_DIR = Path(os.getenv('APPDATA')) / '.browseros' / 'memory'
WORKSPACE_DIR = Path(os.getenv('APPDATA')) / '.browseros' / 'sessions'

# Discord webhook
DISCORD_WEBHOOK = "https://discord.com/api/webhooks/1483478506070474922/ReIZsU3KTpXqNseTWFBNsuPJ-FbYgqEuCTELtMHRWw4ND8vVjMUr36b6LyusiOoJn66d"

# Polymarket API
POLYMARKET_API = "https://polymarket.com/api"

def log_status(phase, message):
    """Print status report to chat"""
    print(f"[{phase}] {message}")

def send_to_discord(content):
    """Send message to Discord webhook"""
    try:
        response = requests.post(DISCORD_WEBHOOK, json={"content": co

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/run_polymarket_brain.py (reported line 17)May include surrounding context.

python
#!/usr/bin/env python3
"""
Polymarket Brain Orchestrator v1.3
Main workflow: CNBC Fetch → Classify → Analyst (geo/macro) → Polymarket → Discord
"""

import subprocess
import sys
import os
import json
import re
from pathlib import Path
from datetime import datetime, timedelta

# Force UTF-8 encoding for Windows console
if sys.platform == 'win32':
    os.environ['PYTHONIOENCODING'] = 'utf-8'
    import io
    sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding='utf-8', errors='replace')
    sys.stderr = io.TextIOWrapper(sys.stderr.buffer, encoding='utf-8', errors='replace')

# Paths
SKILLS_ROOT = Path(os.environ.get('SKILLS_ROOT', 'C:/Users/Legion 5i Pro/.openclaw/workspace/skills'))
POLYMARKET_BRAIN = SKILLS_ROOT / 'polymarket-brain'
CNBC_FETCHER = SKILLS_ROOT / 'cnbc-geopolitics-fetcher'
FED_AGENT = SKILLS_ROOT / 'the-fed-agent'
POLYMARKET_ANALYST = SKILLS_ROOT / 'polymarket-analyst'
GEOPOLITICS_EXPERT = SKILLS_ROOT / 'geopolitics-e

Tainted flow: 'content' from os.environ.get (line 50, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/run_polymarket_brain.py (reported line 65)May include surrounding context.

python
return False
    
    try:
        response = requests.post(webhook, json={'content': content}, timeout=10)
        return response.status_code == 204
    except Exception as e:
        print(f"⚠️ Discord error: {e}")

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/send_discord.py (reported line 11)May include surrounding context.

python
#!/usr/bin/env python3
"""Send Discord Messages — Real analyst data, exact format"""

import os
import json
import requests
from datetime import datetime

# Paths
SCRIPTS_DIR = os.path.dirname(__file__)
SKILLS_DIR = os.path.join(os.environ['USERPROFILE'], '.browseros', 'skills')
MARKETS_FILE = os.path.join(SCRIPTS_DIR, '..', 'output', 'polymarket_markets.json')
FED_TOPICS_FILE = os.path.join(SCRIPTS_DIR, '..', 'output', 'fed_topics.json')
GEO_TOPICS_FILE = os.path.join(SCRIPTS_DIR, '..', 'output', 'geo_topics.json')

def load_config():
    """Load webhook from config.md"""
    config_path = os.path.join(SCRIPTS_DIR, '..', 'references', 'config.md')
    try:
        with open(config_path, 'r', encoding='utf-8') as f:
            for line in f:
                if 'discord.com/api/webhooks' in line:
                    r

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file contains a live hard-coded Discord webhook URL and describes automated outbound posting behavior. A webhook is effectively a credential; exposing it in skill content enables unauthorized message posting, spam, impersonation, and possible leakage of analyzed data to a third-party endpoint without clear justification or access controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file exposes a hard-coded Discord webhook URL in natural-language documentation, which is equivalent to publishing a secret token. Anyone who can read the file can post to the Discord channel, abuse the integration, or leverage it as an exfiltration sink, and the surrounding persistence language makes the risk more serious rather than less.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow summary describes fetching news, generating analysis, matching markets, and sending results to Discord, but it does not clearly warn that external content and potentially sensitive derived analysis will be transmitted off-platform. Because the file also shows a configured Discord webhook and positions the workflow as ready to use, users may enable or trust data egress they do not fully understand.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file exposes a Discord webhook token-like endpoint directly in documentation, which is a sensitive integration secret because anyone with the full webhook URL can post messages into the associated Discord channel. In this skill context, the secret is embedded alongside orchestration and persistence instructions, increasing the likelihood of reuse, leakage, and unauthorized notifications or spam if the repository, skill bundle, or logs are shared.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · PRE_TEST_CHECKLIST.md (reported line 41)May include surrounding context.

📋 Recommended Test Flow

  1. Clear history (for fresh test):
    text
    type nul > ..\cnbc-geopolitics-fetcher\references\sent_urls.txt
    

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 407)May include surrounding context.

📋 Recommended Test Flow

  1. Clear history (for fresh test):
    text
    type nul > ..\cnbc-geopolitics-fetcher\references\sent_urls.txt
    

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 50)May include surrounding context.

python
## 📋 Recommended Test Flow

1. **Clear history** (for fresh test):
   ```
   type nul > ..\cnbc-geopolitics-fetcher\references\sent_urls.txt
   ```

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly embeds real Discord webhook endpoints/IDs while also advising that such secrets should never be committed. Webhooks are bearer credentials: anyone who obtains them can post arbitrary messages into the target Discord channels, spam, spoof workflow output, or use them as an exfiltration sink.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

python polymarket_brain_orchestrator.py

text

### Fresh Test (Clear History)
```cmd
type nul > C:\Users\Legion 5i Pro\.browseros\skills\cnbc-geopolitics-fetcher\references\sent_urls.txt
cd C:\Users\Legion 5i Pro\.browseros\skills\polymarket-brain

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

This command truncates the history file directly, which manipulates operational state used to prevent duplicate posting. In context it is presented as a test convenience, but if executed casually or against production state it can force reposting of previously processed content and erase audit-like tracking of what was sent.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 348)May include surrounding context.

md
# Check history file:
type ..\cnbc-geopolitics-fetcher\references\sent_urls.txt

# Clear history (test mode):
type nul > ..\cnbc-geopolitics-fetcher\references\sent_urls.txt

# Validate URLs:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains live Discord webhook URLs embedded directly in source code and uses them to transmit content externally. Webhooks are secrets that grant posting capability; if the code is shared or leaked, third parties can abuse the channels, spam them, or impersonate this automation, and the skill sends data off-host without meaningful user disclosure.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 262)May include surrounding context.

md
OUTPUT_DIR = Path(__file__).parent / "output"
OUTPUT_DIR.mkdir(exist_ok=True)

# Mode: "TEST" (clear history) or "PROD" (keep history)
MODE = os.environ.get("POLYMARKET_BRAIN_MODE", "PROD")

# ============================================================================

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 294)May include surrounding context.

md
OUTPUT_DIR = Path(__file__).parent / "output"
OUTPUT_DIR.mkdir(exist_ok=True)

# Mode: "TEST" (clear history) or "PROD" (keep history)
MODE = os.environ.get("POLYMARKET_BRAIN_MODE", "PROD")

# ============================================================================

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 37)May include surrounding context.

python
OUTPUT_DIR = Path(__file__).parent / "output"
OUTPUT_DIR.mkdir(exist_ok=True)

# Mode: "TEST" (clear history) or "PROD" (keep history)
MODE = os.environ.get("POLYMARKET_BRAIN_MODE", "PROD")

# ============================================================================

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 59)May include surrounding context.

python
print(f"  ✓ Cleared: {history_file}")
    
    # Set environment variable for Discord webhook
    env = os.environ.copy()
    env["DISCORD_WEBHOOK"] = PHASE1_DISCORD_WEBHOOK
    
    # Save Phase 1 output to JSON for Phase 2 to consume

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · polymarket_brain_orchestrator.py (reported line 311)May include surrounding context.

python
print(f"Time: {datetime.now().strftime('%Y-%m-%d %H:%M UTC')}")
    print("\nAll recent CNBC geopolitics articles have already been analyzed.")
    print("Skipping analysis phases (no new content).")
    print("\nNext: Run again later for fresh articles, or use TEST mode to reset history.")
    print("="*60)

# ============================================================================

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a live Discord webhook URL directly in source code, creating a built-in outbound exfiltration channel and exposing a secret credential to anyone who can read the file. In the context of an agent skill with no trusted metadata or justified communication requirement, this enables unauthorized remote posting and easy reuse of the webhook by third parties.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code performs external POST requests to Discord, sending generated content off-host without any user approval, policy gate, or clear runtime disclosure. In an unknown-purpose skill, unsolicited network egress is dangerous because it can be repurposed to exfiltrate data or act as an unauthorized command-and-control/output channel.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.