Back to skill

Security audit

Polymarket Market Importer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a clearly disclosed Polymarket-to-Simmer importer with expected API-key use, scheduled operation, and local deduplication state, though users should review live-mode automation and dependency pinning.

Install only if you are comfortable giving the skill a Simmer API key and allowing it to import matching markets when run with --live. Start with dry-run, keep max_per_run conservative, review the cron/autostart behavior in your OpenClaw setup, and prefer a pinned or reviewed simmer-sdk version if using this in a serious account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Security-Sensitive Third-Party Dependency

Content
View full analysis
Remediation
View remediation
``` Install it with: ```bash pip install --require-hashes -r requirements.txt ``` 3. Pin and hash all transitive dependencies, not only the direct SDK dependency. 4. Restrict installation to an approved package index and prevent fallback to untrusted or user-controlled indexes. 5. Review dependency updates before changing the pinned version. Include vulnerability scanning, provenance verification, and release-diff inspection in the update process. 6. Run the skill under a dedicated, least-privileged account or container. Expose only the required API credential and files to limit the consequences of dependency compromise. 7. Scope and rotate `SIMMER_API_KEY` where supported, and monitor the account for unexpected imports or other API activity. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
market_importer.py:222
Finding

Unsanitized Remote Market Data Written to Terminals and Logs

Content
View full analysis
Remediation
View remediation
str: text = ANSI_ESCAPE.sub("", str(value)) output = [] for char in text: category = unicodedata.category(char) if char in "\n\r\t" or category.startswith("C"): output.append(char.encode("unicode_escape").decode("ascii")) else: output.append(char) return "".join(output) ``` 2. Apply the sanitizer to `question`, `mid`, timestamps, exception text, and any other value originating from an API, persisted state, or third-party library before printing: ```python print( f' Importing: "{safe_display(question)}" ' f"(vol: ${volume:,.0f})" ) ``` 3. Use structured JSON logging for scheduler and monitoring integrations. Ensure the logging library serializes control characters rather than emitting them as raw terminal bytes. 4. Keep raw remote values separate from display-safe values. If preserving the original title is necessary, store it in structured data but sanitize it at every output boundary. 5. Limit the maximum length of displayed market titles and identifiers to prevent oversized log entries and terminal disruption. 6. Add tests covering ANSI control sequences, carriage returns, newlines, bidirectional text controls, null bytes, and excessively long titles. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation indicates capabilities involving environment variables and likely file/state writes, but the manifest does not declare any tool scope or permissions. This creates an authorization and review gap: users and platforms cannot easily assess what resources the skill expects to access, increasing the chance of over-privileged execution or unsafe deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation advertises a '--live' mode and a recurring schedule, but it does not prominently warn that this will perform real imports automatically over time. In an automation context, users may enable live mode without realizing it will continue creating imports on schedule, leading to unintended actions, quota consumption, or trading workflow changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file explains that configuration updates are persisted to a skill config file, which affects user data/state on disk. While the README documents the behavior functionally, it does not clearly warn the user that running the update command will modify local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill stores imported market IDs in imported_markets.json, which is persistent local state related to user activity. The README mentions this in the workflow, but it does not explicitly warn users earlier that the skill writes and retains this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment says 'save anyway for dedup', implying dry-run-discovered markets are persisted, but the surrounding logic only calls save_seen when not dry_run. In dry-run mode, entries are added to the in-memory seen map but never written to disk, so the documentation contradicts actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.