Back to skill

Security audit

Polymarket Eth 5m Mtf Momentum Dyll

Security checks for vulnerabilities and agentic risk

Overview

This is a real trading bot, but it needs Review because it can make live trades, sends a trading API key to a configurable endpoint, and mixes ETH and BTC descriptions.

Install only after reviewing the ETH versus BTC mismatch and the live-trading behavior. Use a dedicated low-scope Simmer key, avoid setting SIMMER_API_URL unless it is a trusted HTTPS Simmer endpoint, pin and review simmer-sdk, and run in paper mode before enabling cron or --live.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
mtf_momentum.py:254
Finding

Trading API Credential Can Be Transmitted to an Arbitrary Endpoint

Content
View full analysis

Vulnerability Details

File Location: mtf_momentum.py:67, mtf_momentum.py:254-262
Vulnerability Type: Credential disclosure through an unrestricted, configurable network destination
Risk Level: High

Vulnerable Code

python
SIMMER_API_URL = os.environ.get("SIMMER_API_URL", "https://api.simmer.markets")
python
def fetch_fast_markets():
    """Fetch active fast markets for the configured asset from Simmer API."""
    try:
        api_key = os.environ.get("SIMMER_API_KEY", "")
        req = Request(
            f"{SIMMER_API_URL}/api/sdk/fast-markets?asset={ASSET}&window=5m&limit=10",
            headers={"Authorization": f"Bearer {api_key}"},
        )
        data = json.loads(urlopen(req, timeout=10).read())
        return data.get("markets", [])
    except Exception as e:
        print(f"  Failed to fetch fast markets: {e}")
        return []

Technical Analysis

The program obtains SIMMER_API_URL from an unrestricted environment variable and sends SIMMER_API_KEY to that destination as a bearer credential. It does not validate the URL scheme, hostname, port, or effective destination after redirects.

Configurability of a credential-bearing endpoint is not required for the declared momentum calculation or trading functionality. Anyone able to influence the process environment can redirect the request to an attacker-controlled HTTP or HTTPS server. Allowing plaintext HTTP also permits disclosure to a network observer.

This behavior explains the sensitive-network-flow pre-scan result. Sending the key to the legitimate Simmer service is necessary, but allowing an arbitrary destination exceeds the minimum trust boundary required by the Skill.

Attack Path

  1. An attacker, compromised launcher, deployment configuration, or automation environment sets SIMMER_API_URL to an attacker-controlled address, such as https://attacker.example.
  2. The user supp ...[truncated 1285 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unrestricted SIMMER_API_URL override and use a fixed trusted endpoint:
    python
    SIMMER_API_URL = "https://api.simmer.markets"
    
  2. If endpoint configurability is operationally necessary, parse the URL and enforce:
    • Scheme exactly equal to https.
    • Hostname present in a small explicit allowlist.
    • No embedded user information.
    • An approved port, normally 443.
  3. Reject redirects for authenticated requests, or implement redirect handling that strips authorization headers and only permits same-origin HTTPS redirects.
  4. Construct authenticated requests through a centralized client that applies destination validation before adding credentials.
  5. Use a narrowly scoped API key with only the permissions required for market discovery and intended trades.
  6. Support immediate key revocation and rotation, and rotate any key that may have been used with an untrusted endpoint.
  7. Do not log the authorization header or API key in errors, debug traces, or automation reports.
  8. Add tests proving that HTTP URLs, unapproved hosts, nonstandard ports, and cross-origin redirects are rejected before the credential is attached.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:41
Finding

Unpinned Third-Party Trading SDK Creates Supply-Chain Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:41-45, SKILL.md:107; clawhub.json:4-12
Vulnerability Type: Unpinned executable dependency without integrity verification
Risk Level: Medium

Vulnerable Code

SKILL.md:

markdown
## Setup

1. Install: `pip install simmer-sdk`
2. Set your API key: `export SIMMER_API_KEY=sk_live_...`
3. Dry run: `python3 mtf_momentum.py`
4. Go live: `python3 mtf_momentum.py --live`

The troubleshooting instructions repeat the unpinned installation command:

markdown
- **"simmer-sdk not installed"** — Run `pip install simmer-sdk`.

clawhub.json:

json
{
  "emoji": "\u26a1",
  "requires": {
    "env": [
      "SIMMER_API_KEY"
    ],
    "pip": [
      "simmer-sdk"
    ]
  },
  "cron": "*/1 * * * *",
  "autostart": false,
  "automaton": {
    "managed": true,
    "entrypoint": "mtf_momentum.py"
  }
}

Technical Analysis

The Skill installs and imports simmer-sdk without specifying a reviewed version or package hash. Consequently, installations performed at different times can resolve to different package contents. The audit cannot verify the SDK implementation because it is not included in the project.

This dependency is security-sensitive: it receives SIMMER_API_KEY, queries private portfolio information, retrieves positions, and submits trades. A compromised or unexpectedly changed release would execute in the Skill process with access to its environment and trading authority.

The issue is not evidence that the current upstream package is malicious. The vulnerability is the absence of reproducible version and integrity controls around a privileged dependency.

Attack Path

  1. An attacker compromises the upstream package account, publishing pipeline, package index, or another part of the dependency distribution chain.
  2. A malicious or compromised simmer-sdk release becomes the version sel ...[truncated 1239 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin simmer-sdk to an exact reviewed version in both documentation and package metadata, for example:
    text
    simmer-sdk==X.Y.Z
    
  2. Use a lockfile or requirements file with cryptographic hashes and install with hash enforcement:
    text
    pip install --require-hashes -r requirements.txt
    
  3. Ensure the dependency declaration in clawhub.json resolves to the same reviewed version rather than an unconstrained latest release.
  4. Install only from an explicitly configured trusted package index, preferably with dependency-confusion protections.
  5. Review new SDK versions before updating the pin, including package ownership, release provenance, transitive dependencies, and credential-handling behavior.
  6. Run the Skill as a dedicated, unprivileged account with restricted filesystem and network access.
  7. Provide a narrowly scoped trading key and avoid exposing unrelated secrets in the process environment.
  8. Add dependency vulnerability and provenance checks to the release process, and record hashes for the complete resolved dependency set.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · mtf_momentum.py (reported line 180)May include surrounding context.

python
url = f"{BINANCE_KLINE_URL}?symbol={symbol}&interval={interval}&limit={limit}"
    try:
        req = Request(url, headers={"User-Agent": "SimmerMTFMomentum/1.0"})
        data = json.loads(urlopen(req, timeout=10).read())
        return data
    except Exception as e:
        print(f"  Binance kline fetch failed: {e}")

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request URL is built from SIMMER_API_URL, which is read from the environment and then used directly in urlopen along with an Authorization bearer token. If an attacker can influence the environment, they can redirect this request to an arbitrary host and exfiltrate the API key, making this especially dangerous in automation or containerized deployments where environment variables are commonly injected.

Content

Scanner excerpt · mtf_momentum.py (reported line 261)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/fast-markets?asset={ASSET}&window=5m&limit=10",
            headers={"Authorization": f"Bearer {api_key}"},
        )
        data = json.loads(urlopen(req, timeout=10).read())
        return data.get("markets", [])
    except Exception as e:
        print(f"  Failed to fetch fast markets: {e}")

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding points to a broader description-behavior mismatch: the skill claims specific Binance-based multi-timeframe momentum logic, but the provided file is primarily operational documentation and Simmer usage guidance rather than verifiable trading logic. That is dangerous because users may trust unverified claims about strategy behavior and risk controls when deciding to enable live trading.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to a broader description-behavior mismatch: the skill claims specific Binance-based multi-timeframe momentum logic, but the provided file is primarily operational documentation and Simmer usage guidance rather than verifiable trading logic. That is dangerous because users may trust unverified claims about strategy behavior and risk controls when deciding to enable live trading.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example output shows a BTC market even though the skill is branded as ETH momentum. Example output is often treated by users as authoritative expected behavior, so this contradiction can lead to incorrect deployment, monitoring errors, or unnoticed mis-trades in a financial system.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata says it is for BTC fast markets, but the implementation hardcodes ETH trading. In a live trading context, strategy/asset mismatch is security-relevant because users may authorize execution under false assumptions, leading to unintended real-money trades on the wrong market.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises executable trading behavior and explicitly instructs users to set an API key and run live trading, but it does not declare any tool scope or permissions despite requiring environment access and network connectivity. This weakens reviewability and consent boundaries, making it easier for a user or platform to authorize behavior they did not clearly expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation inconsistently refers to ETH and BTC markets in a live trading skill. In this context, inconsistent asset identification is not merely editorial; it can mislead users about what instrument is being traded and what external data informs decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes a one-command path to live trading without an explicit warning about real-money execution, loss risk, or the need to test in paper mode first. In a trading skill, this increases the chance of accidental real-money activation and unsafe operator behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for 'Polymarket BTC 5-minute fast markets', while this file's top-level docstring and constants clearly implement ETH/USDT momentum and ETH fast-market trading. This is an active contradiction about the asset and market scope, not merely an omitted detail.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mtf_momentum.py (reported line 68)May include surrounding context.

python
SLIPPAGE_MAX_PCT = 0.15

SIMMER_API_URL = os.environ.get("SIMMER_API_URL", "https://api.simmer.markets")
BINANCE_KLINE_URL = "https://api.binance.com/api/v3/klines"

# ---------------------------------------------------------------------------
# SimmerClient singleton

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Passing --live immediately enables real trades without an interactive confirmation, second factor, or explicit acknowledgment of account/venue/size. In automated or copied-command scenarios, this increases the risk of accidental financial loss from user error, scripting mistakes, or deceptive invocation guidance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for Polymarket BTC 5-minute fast markets, but this file identifies its trade source as "sdk:eth-mtf-momentum" and labels the asset as "ETH". The code then retrieves portfolio and positions for that ETH strategy, which does not match the stated BTC/Polymarket scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring says the script "Shows active positions and recent signals," but the implementation only fetches portfolio and positions, then prints balances, active/resolved counts, PnL, and win rate. No signal retrieval or display logic is present, so the documentation overstates what the script does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.