Back to skill

Security audit

polymarket-sports-trade

Security checks for vulnerabilities and agentic risk

Overview

This is a real-money PolySports trading skill with disclosed trading automation, but it handles trading credentials in unsafe chat and persistent cron-job text.

Install only if you are prepared to grant an agent access to PolySports account data and possible real trades. Do not paste a live API key into chat or store it in cron payloads; use a protected secret mechanism, set explicit position sizes and spending limits, review any enabled schedules, and rotate any key that has already been shared in a transcript or saved job.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
assets/cron/jobs.template.json:15
Finding

Trading API Key Stored in a Persistent Cron Job Payload

Content
View full analysis

Vulnerability Details

File Location: assets/cron/jobs.template.json:15 and references/trading-playbook.md:32
Vulnerability Type: Plaintext credential storage in persistent automation configuration
Risk Level: High

Relevant code:

json
"payload": {
  "kind": "agentTurn",
  "message": "...执行本任务时涉及的占位符:\n- PolySports API Key: __POLYSPORTS_API_KEY__\n- Telegram target: telegram:__TELEGRAM_CHAT_ID__\n- 所有 PolySports 请求都必须显式带 `X-PolySports-Api-Key`、`X-PolySports-Skill: polysports-trading-agent`、`X-PolySports-Client: chatgpt`..."
}
markdown
- Fill placeholders such as `__POLYSPORTS_API_KEY__`, `__TELEGRAM_CHAT_ID__`, and `__POSITION_SIZE_USDC__` before enabling a job.

Technical Analysis

The cron template places __POLYSPORTS_API_KEY__ directly inside the persistent payload.message, and the playbook instructs the operator to replace that placeholder before enabling the job. Following these instructions results in a reusable trading credential being stored as plaintext within an OpenClaw cron definition.

Persistent task definitions can be exposed through cron administration interfaces, configuration files, job exports, backups, debugging output, agent execution transcripts, or logs. The template also sets enabled to true and deleteAfterRun to false, so the job and its embedded credential are intended to remain available across runs.

The scheduled workflow reads balances, positions, authorization state, and markets and may place real trades. Consequently, exposure of the credential is more serious than disclosure of a read-only integration token. The precise impact depends on the scopes and trading authorization associated with the API key.

Attack Path

  1. A user or operator replaces __POLYSPORTS_API_KEY__ with a real API key as instructed.
  2. OpenClaw stores the resulting cron job, including the plaintext key in payload.message.
  3. An attacker gains read access to ...[truncated 960 chars]
Remediation
View remediation

Remediation Suggestions

  • Never place the actual API key in payload.message, command-line arguments, delivery messages, or other persistent job metadata.
  • Store credentials in a dedicated secret manager or protected OpenClaw credential binding.
  • Put only an opaque secret reference in the cron definition and resolve it at execution time.
  • Prevent secrets from appearing in job exports, administrative views, debug output, model context, and execution logs.
  • Use separate automation credentials with only the required scopes. A market scan should use read-only permissions unless trading is explicitly enabled.
  • Prefer time-limited or time-boxed authorization for short-lived monitoring jobs.
  • Ensure short-lived jobs delete both their schedules and any associated credential bindings after completion.
  • Provide a documented disable, deletion, and credential-rotation procedure.
  • If users have already embedded API keys in cron payloads, delete or sanitize those jobs and rotate the exposed keys.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:19
Finding

Reusable Trading API Key Requested Through Conversation History

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19 and references/skills-api.md:10
Vulnerability Type: Sensitive credential collection through conversational text
Risk Level: Medium

Relevant code:

markdown
- If the API key is missing, ask the user to send it directly in the conversation. If they do not have one, send them to `https://polysports.vip` to create it.
markdown
- If the API key is missing, first ask the user to send their PolySports API key directly in the conversation so it can be used for this skill session.

Technical Analysis

The Skill explicitly instructs users to disclose a reusable PolySports API key directly in the conversation. Conversation content may be retained in chat history, copied into agent contexts, exported for support or debugging, included in telemetry, or made accessible to users and systems that can inspect transcripts.

A trading credential should be treated as a secret and supplied through a protected credential-entry mechanism rather than ordinary conversational text. Even if transport encryption is present, transcript retention and propagation increase the number of locations in which the credential may exist.

The risk is amplified by the API's support for persistent trading authority. A key recovered from a transcript may remain usable after the original conversation ends unless it is independently expired or revoked.

Attack Path

  1. The Skill asks the user to paste a PolySports API key into the conversation.
  2. The user supplies the key as ordinary chat content.
  3. The conversation is retained, exported, logged, copied into another agent context, or viewed by someone with transcript access.
  4. An attacker or unauthorized operator recovers the plaintext key.
  5. The key is replayed against the documented PolySports API host.
  6. The attacker performs account reads or trading actions permitted by the key's scopes and current authorization ...[truncated 548 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the instruction to paste the API key into chat with a secure credential-entry or secret-injection workflow.
  • Keep the secret outside model-visible conversation history wherever the runtime supports protected credential bindings.
  • Ensure user interfaces mask the credential and do not include it in transcript exports, telemetry, logs, or delivery notifications.
  • Never repeat or summarize the API key in agent output.
  • Issue narrowly scoped credentials, separating read-only market access from trading access where possible.
  • Prefer expiring credentials and time-boxed trading authorization over indefinitely reusable keys.
  • Provide users with a direct revocation and rotation process.
  • Warn users to rotate any key previously posted in a retained conversation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the user to paste a live PolySports API key into the chat conversation for session use. That is dangerous because chat transcripts may be retained, exposed to other tools or operators, or mishandled by downstream components, turning a bearer credential into an easily recoverable secret that can authorize trading or account access.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a true credential-handling flaw: the documentation normalizes pasting an API key directly into the conversation, where it may be logged, stored, or included in later context. In this skill, the danger is elevated because the same credential is then used for authenticated balance checks, authorization flows, and potentially real-money trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to ask the user to paste a live X-PolySports-Api-Key into the conversation. Chat channels are often logged, retained, or exposed to broader model/context processing, so collecting long-lived trading credentials in plain conversation materially increases the risk of credential theft and unauthorized trading activity.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This instruction normalizes collecting sensitive API credentials directly in the chat transcript for a skill that can place real trades. In this context, exposure of the API key could let an attacker or any downstream party with transcript access query account data, place orders, or manipulate automation, making the risk more severe than in a non-financial skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file states that the saved rule-setting window is 23:00 in Asia/Shanghai, which is a locale-specific constraint expressed in natural language. There is no user opt-in, choice, or justification that this skill must operate in that timezone, so it creates a locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scheduled job message is an open-ended autonomous trading instruction that directs the agent to inspect balances, authorizations, markets, and potentially place real trades, create follow-on monitoring jobs, and send Telegram notifications. Because it lacks hard trigger constraints, risk limits, explicit approval gates, or environment checks, a scheduled run could execute financially sensitive actions repeatedly or in unintended contexts, making this materially dangerous in a trading skill.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · assets/templates/monitor-launcher.prompt.md (reported line 5)May include surrounding context.

md
Read first:

- `skills/polysports-trading-agent/SKILL.md`
- `skills/polysports-trading-agent/references/skills-api.md`
- `skills/polysports-trading-agent/references/monitoring-rules.md`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook hard-codes a default automation window of 23:00 in Asia/Shanghai without requiring user opt-in or verifying the user's actual timezone. In a trading automation context, an incorrect timezone can cause scans or orders to run at unintended times, potentially missing markets, acting on stale assumptions, or triggering trades outside the user's expected schedule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction explicitly says "输出必须使用中文", forcing a specific language for all outcomes. This is a natural-language locale policy issue because it does not offer the user a language choice or document a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file describes deleting short-lived monitoring tasks after they no longer matter or after a successful exit. While operationally reasonable, the playbook does not explicitly warn the user that automation may remove existing monitoring jobs/tasks, which affects system state and could matter for auditability or recovery.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.