Back to skill

Security audit

Polymarket Sol 5m Mtf Momentum Dyll

Security checks for vulnerabilities and agentic risk

Overview

This is a real trading automation skill with disclosed dry-run/live modes, but its market scope, credential handling, and dependency controls need careful review before installation.

Install only after confirming this is meant to trade SOL 5-minute markets through Simmer, not BTC directly on Polymarket. Use a minimally scoped API key, do not set SIMMER_API_URL unless you fully trust the destination, pin and review simmer-sdk, keep dry-run mode until tested, and enable cron/live trading only with explicit risk limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
mtf_momentum.py:256
Finding

API Credential Can Be Redirected to an Arbitrary Network Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:8
Finding

Security-Critical Third-Party Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
``` 2. Use a lock file or requirements file containing cryptographic hashes, and install with hash verification: ```bash pip install --require-hashes -r requirements.txt ``` 3. Update `clawhub.json` and `SKILL.md` consistently so automated and manual installation use the same audited version. 4. Install only from a trusted, explicitly configured package index. Disable unneeded extra indexes to reduce dependency-confusion exposure. 5. Review package ownership, release provenance, transitive dependencies, and changelogs before upgrades. Test upgrades in an isolated environment before deployment. 6. Run the Skill with a dedicated low-privilege operating-system account and a minimally scoped API key to reduce the impact of dependency compromise. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · mtf_momentum.py (reported line 180)May include surrounding context.

python
url = f"{BINANCE_KLINE_URL}?symbol={symbol}&interval={interval}&limit={limit}"
    try:
        req = Request(url, headers={"User-Agent": "SimmerMTFMomentum/1.0"})
        data = json.loads(urlopen(req, timeout=10).read())
        return data
    except Exception as e:
        print(f"  Binance kline fetch failed: {e}")

Tainted flow: 'req' from os.environ.get (line 257, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request target is built from SIMMER_API_URL, which is environment-controlled, and the code attaches the SIMMER_API_KEY as a Bearer token header before calling urlopen. If an attacker can influence the environment or deployment configuration, they can redirect this request to an attacker-controlled host and capture the API key, making this a real credential exfiltration risk.

Content

Scanner excerpt · mtf_momentum.py (reported line 261)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/fast-markets?asset={ASSET}&window=5m&limit=10",
            headers={"Authorization": f"Bearer {api_key}"},
        )
        data = json.loads(urlopen(req, timeout=10).read())
        return data.get("markets", [])
    except Exception as e:
        print(f"  Failed to fetch fast markets: {e}")

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation describes one strategy and market context, but the detected behavior references different assets, different platform resources, and additional portfolio/status operations not clearly disclosed in the declared purpose. In a trading skill, this ambiguity is dangerous because users may grant trust or permissions based on a false understanding of what accounts, markets, and operations the skill will actually touch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation describes one strategy and market context, but the detected behavior references different assets, different platform resources, and additional portfolio/status operations not clearly disclosed in the declared purpose. In a trading skill, this ambiguity is dangerous because users may grant trust or permissions based on a false understanding of what accounts, markets, and operations the skill will actually touch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest description frames the skill as targeting Polymarket BTC 5-minute fast markets, but the implementation hard-codes ASSET = "SOL" and BINANCE_SYMBOL = "SOLUSDT". This is a direct semantic mismatch in the traded instrument, not an implementation detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script is hard-coded to SOL and a Simmer trade source even though the skill metadata describes Polymarket BTC 5-minute markets. This mismatch can cause operators to review the wrong asset and venue status, leading to incorrect trading decisions, missed risk exposure, and false assurance about strategy state.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents behavior that depends on environment variables and external network access, but it does not declare any explicit tool scope or permissions. In an agent ecosystem, missing scope declarations reduce transparency and can cause users or orchestrators to approve a skill without understanding that it can access secrets and communicate externally, which is especially risky for a trading bot handling API keys and live actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and body text conflict on the traded asset and market source, undermining the integrity of the documentation. In a finance-related skill, inconsistent asset/source labeling can cause an operator to deploy the strategy under false assumptions, making accidental misuse materially more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example output shows a BTC market trade even though the skill is presented as a SOL strategy, which can train users to expect the wrong runtime behavior. Examples are often treated as operational truth, so this contradiction increases the chance of executing against an unintended market and suffering financial mistakes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises a --live mode for executing trades but does not prominently warn that real funds can be used and lost. In trading automation, insufficient risk disclosure can lead users to trigger irreversible financial actions without informed consent, especially when setup instructions and command examples make live execution seem routine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description claims trading for Polymarket fast markets, but the code is implemented against api.simmer.markets and SimmerClient, including market discovery and trade execution through Simmer-specific interfaces. That may still be related infrastructure, but as written the manifest does not accurately describe the actual trading venue/integration used by the code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mtf_momentum.py (reported line 68)May include surrounding context.

python
SLIPPAGE_MAX_PCT = 0.15

SIMMER_API_URL = os.environ.get("SIMMER_API_URL", "https://api.simmer.markets")
BINANCE_KLINE_URL = "https://api.binance.com/api/v3/klines"

# ---------------------------------------------------------------------------
# SimmerClient singleton

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring claims this status tool 'Shows active positions and recent signals,' but the implementation only calls get_portfolio() and get_positions() and reports balances, positions, PnL, and win rate. There is no retrieval or display of any signal history, so the documentation overstates what the script does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The top-level documentation states the skill 'Reads 1m/3m/5m Binance SOL/USDT returns', which implies direct multi-timeframe inputs. In reality, the code fetches only 1-minute klines and computes 3-minute and 5-minute returns synthetically from that single stream.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.