Back to skill

Security audit

Polymarket Btc 5m Mtf Momentum Dyll

Security checks for vulnerabilities and agentic risk

Overview

This trading bot mostly matches its stated purpose, but it needs review because its API key can be sent to an environment-controlled endpoint and its trading SDK dependency is unpinned.

Install only if you trust the publisher and can run it in a restricted environment. Use a least-privileged Simmer API key, do not set SIMMER_API_URL unless it is the official HTTPS endpoint, pin or review simmer-sdk before installation, start in paper mode, and enable --live only with clear trade limits and monitoring.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
mtf_momentum.py:245
Finding

Trading API key can be transmitted to an arbitrary environment-controlled endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Security-sensitive third-party SDK is installed without version or artifact pinning

Content
View full analysis
Remediation
View remediation
" ] ``` 2. Update the setup documentation to install the same exact version rather than the latest available release. 3. Use a lock file or hash-verified requirements file, for example with `--require-hashes`, so installation verifies the expected package artifact. 4. Retrieve dependencies only from an approved package index over TLS. Avoid untrusted extra indexes or dependency sources. 5. Review release provenance, signatures, maintainers, and package metadata before upgrading. Apply upgrades through a controlled review process rather than automatically resolving new releases. 6. Run the Skill in a restricted environment with: - Minimal filesystem permissions. - Network egress limited to required Binance and Simmer endpoints. - A least-privileged API key. - No unrelated secrets in the process environment. 7. Monitor installed dependency versions and package integrity in deployment logs or software-bill-of-materials records. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · mtf_momentum.py (reported line 180)May include surrounding context.

python
url = f"{BINANCE_KLINE_URL}?symbol={symbol}&interval={interval}&limit={limit}"
    try:
        req = Request(url, headers={"User-Agent": "SimmerMTFMomentum/1.0"})
        data = json.loads(urlopen(req, timeout=10).read())
        return data
    except Exception as e:
        print(f"  Binance kline fetch failed: {e}")

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request target is derived from SIMMER_API_URL, an environment variable, and the code also attaches the SIMMER_API_KEY as a Bearer token. If an attacker can influence the environment, they can redirect this request to an arbitrary host and exfiltrate the API key, which is especially dangerous in an automated trading skill.

Content

Scanner excerpt · mtf_momentum.py (reported line 261)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/fast-markets?asset={ASSET}&window=5m&limit=10",
            headers={"Authorization": f"Bearer {api_key}"},
        )
        data = json.loads(urlopen(req, timeout=10).read())
        return data.get("markets", [])
    except Exception as e:
        print(f"  Failed to fetch fast markets: {e}")

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose centers on momentum trading logic, but the skill also advertises portfolio, position, and status interactions that imply access to sensitive account data not clearly disclosed in the main description. This mismatch undermines informed consent and can cause users to authorize a trading skill that also reads account state beyond what they reasonably expect.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that require environment access and network access but does not declare any explicit tool scope or permission boundaries. In an agent setting, missing scope declarations can lead to overbroad execution privileges and make it harder for operators to understand or constrain what the skill may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides a direct path from dry run to '--live' execution without a prominent warning that this may place real-money trades and cause irreversible financial loss. In a trading context, weak safety messaging materially increases the chance of accidental live execution, especially when the instructions are simple and action-oriented.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mtf_momentum.py (reported line 68)May include surrounding context.

python
SLIPPAGE_MAX_PCT = 0.15

SIMMER_API_URL = os.environ.get("SIMMER_API_URL", "https://api.simmer.markets")
BINANCE_KLINE_URL = "https://api.binance.com/api/v3/klines"

# ---------------------------------------------------------------------------
# SimmerClient singleton

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code emits a fallback automaton report unconditionally whenever AUTOMATON_MANAGED is set, even after the strategy may already have printed a real report. This can produce contradictory status output such as reporting both executed trades and a final no_signal result, which can corrupt downstream automation, monitoring, or control logic in an automated trading environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description explains the skill's purpose in broad marketing language but does not specify concrete invocation phrases, scope limits, or when the skill should not be used. For a markdown/manifest file, this can create ambiguous activation behavior if the description is used for skill routing or discovery.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest and module description present this as a trading strategy that reads Binance data and trades Polymarket fast markets. In addition to that core behavior, the file exposes a --set path that updates and saves configuration to disk, which is a separate state-modifying capability not described in the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

A momentum trading skill would be expected to fetch market data, evaluate signals, and optionally place trades. Writing updated settings to a config file is an auxiliary capability that is not mentioned in the manifest description and is not obviously required for executing the strategy itself.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring says the script provides 'Quick status' and 'Shows active positions and recent signals,' but the implementation also retrieves and displays overall portfolio balance via client.get_portfolio(). Portfolio-level account balance is adjacent functionality, but it is broader than the narrow behavior described in the file documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.