Back to skill

Security audit

Polymarket Btc Midcandle

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed real-money trading bot, but it deserves Review because it can run unattended live trades and relies on high-trust credentials and dependencies with weak safeguards.

Review this carefully before installing. Use a dedicated low-limit trading key, run paper mode first, avoid cron until you understand the strategy, do not use `--no-safeguards` casually, pin and review `simmer-sdk`, and only configure a trusted HTTPS Discord webhook destination. The current script also appears broken because a missing `max_consecutive_losses` config key causes startup failure.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned High-Trust Trading SDK Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
btc_midcandle.py:303
Finding

Unrestricted Webhook Destination Permits Blind Server-Side Requests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose understates the skill's effective capabilities by omitting external Binance data access, Discord webhook exfiltration paths, local state persistence, and broader account/position management functions. That mismatch is dangerous because users may approve a trading strategy while unknowingly granting network, persistence, and account-management behaviors that materially expand the attack surface and operational risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises operational behavior that implies access to environment variables, local files, and network services, but it does not declare any tool scope or permissions boundary. In an agent ecosystem, that omission prevents users and platforms from understanding or constraining what the skill can access, increasing the risk of over-privileged execution and unintended data or trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents real-money trading and an explicit '--no-safeguards' mode, but the warning language is not strong or specific enough for commands that can directly cause financial loss. In this context, normalizing a protection-bypass flag without prominent risk disclosure can lead operators to disable controls they do not fully understand, increasing the chance of runaway or unsafe trading behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

5. Set up cron (recommended)

bash
crontab -e

Add:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation advertises --set configuration updates, but in fallback mode update_config is never defined and the code only catches the resulting exception after presenting the feature as supported. This is primarily a trust/safety issue: operators may believe risk controls like bet sizing were changed when they were not, leading to unintended live-trading behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The --live flag enables real-money trading immediately with no interactive confirmation, cooldown, or secondary safety check. In an automation context, a typo, copied command, or malicious wrapper invocation can cause unintended live trades with direct financial impact.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code references _config["max_consecutive_losses"], but that key is not defined in CONFIG_SCHEMA, so the script will raise a KeyError at import time before any trading logic runs. In a real-money trading skill, this creates a reliable denial-of-service condition and indicates incomplete or unsafe state/risk-control code paths.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · btc_midcandle.py (reported line 224)May include surrounding context.

python
return in_window, mins_remaining, candle_start

def binance_klines(interval, limit, retries=2):
    url = f"https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval={interval}&limit={limit}"
    for attempt in range(retries):
        try:
            req = _ur.Request(url, headers={"User-Agent": "simmer-btcmc/1.0"})

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · btc_midcandle.py (reported line 257)May include surrounding context.

python
return in_window, mins_remaining, candle_start

def binance_klines(interval, limit, retries=2):
    url = f"https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval={interval}&limit={limit}"
    for attempt in range(retries):
        try:
            req = _ur.Request(url, headers={"User-Agent": "simmer-btcmc/1.0"})

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

When DISCORD_WEBHOOK is configured, the skill silently sends trade details to an external Discord endpoint without prominent runtime disclosure near the operation. This can leak trading behavior, positions, and market activity to third parties, which is especially sensitive for automated real-money strategies.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Although the script describes paper trading as the default, run_strategy() calls get_client(live=not dry_run) even in dry-run mode, which still requires SIMMER_API_KEY and initializes a network client. This undermines operator expectations and can expose credentials or trigger unnecessary external connectivity in contexts assumed to be safe for offline testing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.