Back to skill

Security audit

Polymarket Real Time Trades Stream

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated purpose of streaming Polymarket trades, with disclosed but real handling risks around the Bitquery token and unlocked dependency installation.

Install and run this only in an isolated environment where logs, proxies, and debug tools will not record full WebSocket URLs. Use a limited Bitquery token if available, rotate it if exposure is suspected, and consider pinning dependencies before production use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1
Additional Locations: SKILL.md:98, SKILL.md:139
Vulnerability Type: Unpinned dependency and transitive supply-chain exposure
Risk Level: Medium

Complete Code Snippet:

text
gql[websockets]>=3.4.0

The installation instructions also resolve the dependency without a lock file or integrity hashes:

bash
pip install 'gql[websockets]'

Technical Analysis

The project permits any available version of gql equal to or newer than 3.4.0 and does not lock or hash its transitive WebSocket dependencies. Consequently, the code that users install can differ from the dependency set represented at audit time.

Python packages may execute code during installation and whenever imported. If a future permitted release or one of its transitive dependencies is compromised, the malicious package would execute with the privileges of the user installing or running the skill. The process also has access to BITQUERY_API_KEY, making that credential available to compromised dependency code.

No evidence was found that the currently named package is malicious. The vulnerability is the unconstrained and unverifiable dependency resolution process.

Attack Path

  1. An attacker compromises the publishing account, build pipeline, or distribution channel of a permitted dependency or transitive dependency.
  2. The attacker publishes a malicious release whose version satisfies gql[websockets]>=3.4.0.
  3. A user follows the documented installation command without a reviewed lock file or required hashes.
  4. pip resolves and installs the malicious permitted release.
  5. Malicious installation or import-time code executes with the user's privileges.
  6. The code can read process-accessible files and environment variables, including BITQUERY_API_KEY, and transmit them externally.

Impact Assessment

Successful exploitation provides code e ...[truncated 340 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin gql and every transitive dependency to versions that have been reviewed and tested.
  • Generate and commit a reproducible lock file using a tool such as pip-tools, Poetry, or an equivalent dependency manager.
  • Record package hashes and install with pip install --require-hashes so altered distributions are rejected.
  • Use an internal package mirror or allowlist where appropriate.
  • Run dependency vulnerability and provenance checks in CI.
  • Install dependencies in a dedicated virtual environment or container under a non-privileged account.
  • Establish a controlled process for reviewing and updating pinned versions.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/stream_polymarket.py:216
Finding

API Credential Embedded in WebSocket URL

Content
View full analysis

Vulnerability Details

File Location: scripts/stream_polymarket.py:216-219
Vulnerability Type: Sensitive credential exposure through a URL query parameter
Risk Level: Low

Complete Code Snippet:

python
api_key = get_api_key()
url = f"{BITQUERY_WS_BASE}?{urlencode({'token': api_key})}"
transport = WebsocketsTransport(
    url=url,

Technical Analysis

The Bitquery API key is encoded directly into the WebSocket URL as a token query parameter. This leaves the secret present in the URL string and transport configuration for the lifetime of the connection.

URLs are commonly captured by transport debug logs, exception diagnostics, proxies, network-monitoring systems, application performance monitoring tools, and process instrumentation. The script does not deliberately print the full URL, and SKILL.md explicitly warns users about the risk. Those controls reduce accidental exposure but cannot prevent external infrastructure or third-party library diagnostics from recording the URL.

The project documentation states that URL-based authentication is a Bitquery API limitation. Therefore, the risk cannot necessarily be eliminated locally without upstream support for header-based authentication.

Attack Path

  1. A user starts the stream with BITQUERY_API_KEY configured.
  2. The script constructs a WebSocket URL containing the complete API credential.
  3. Debug logging, an exception handler, a proxy, monitoring infrastructure, or process inspection captures the full URL.
  4. An attacker or unauthorized operator gains access to the captured diagnostic or monitoring data.
  5. The attacker extracts the token query parameter.
  6. The attacker reuses the token to authenticate to Bitquery until the token is revoked, rotated, or expires.

Impact Assessment

Successful exploitation exposes the Bitquery API credential. An attacker may impersonate the affected Bitquery account within the token's ...[truncated 249 chars]

Remediation
View remediation

Remediation Suggestions

  • Use authorization headers instead of URL query parameters if Bitquery introduces support for them.
  • Ensure application, WebSocket transport, proxy, firewall, and monitoring logs redact the token parameter.
  • Add explicit exception handling that reports connection failures without including transport objects or the complete URL.
  • Keep WebSocket and HTTP client debug logging disabled in production.
  • Use a narrowly scoped credential with the minimum available permissions and quota.
  • Run the skill in an isolated environment under a non-privileged account.
  • Avoid passing the constructed URL through command-line arguments or writing it to files.
  • Rotate the credential regularly and immediately after suspected logging or disclosure.
  • Document and test an operational secret-redaction policy for all infrastructure through which the connection passes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill performs network access and reads a sensitive environment variable, but it does not declare any explicit tool scope or permissions boundary. That mismatch can lead users or hosting agents to grant broader capabilities implicitly, reducing transparency around credential use and outbound connectivity for a skill that embeds an API token into a WebSocket URL.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Question: Ethereum Up or Down - March 10, 9:15AM-9:30AM ET
MarketId: 1537455  |  Outcome: Down  (Index 1)
Resolution: https://data.chain.link/streams/eth-usd
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
OutcomeTrade
  Side:       BUY outcome (IsOutcomeBuy: true)

Static analysis

No suspicious patterns detected.