Back to skill

Security audit

Polymarket Edge Liquidity

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent trading automation, but it needs review because live mode can place trades with weak input limits and an unpinned trading SDK dependency.

Review before installing. Use a dedicated low-privilege Simmer API key with spending or transaction limits, keep the default dry-run until behavior is verified, pin and review the `simmer-sdk` dependency, and avoid live mode until probability and trade-amount validation are hardened.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Executable Third-Party Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
edge_liquidity.py:24
Finding

Malformed Probability Values Can Bypass Trade Validation

Content
View full analysis
float: try: return float(value) except Exception: return default def pick_side(prob_yes: float) -> str: # Mean-reversion baseline around 50/50 return "yes" if prob_yes < 0.5 else "no" def expected_edge(prob_yes: float, side: str) -> float: # Simple confidence gap from fair coin baseline (starter strategy style) p = prob_yes if side == "yes" else (1.0 - prob_yes) return abs(p - 0.5) ``` ```python prob_yes = to_float(m.get("current_probability"), 0.5) side = pick_side(prob_yes) edge = expected_edge(prob_yes, side) if edge < min_edge: continue ``` ```python result = client.trade( market_id, side, trade_amount, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `to_float` only verifies that Python can convert a value to `float`. It does not require the result to be finite or within the valid probability range of `0.0` through `1.0`. Python accepts values such as `NaN`, positive or negative infinity, and finite values outside the probability range. These values interact unsafely with the strategy: - For `NaN`, `prob_yes < 0.5` is false, so the strategy selects `"no"`. - Arithmetic involving `NaN` produces `NaN`. - The comparison `edge < min_edge` is also false when `edge` is `NaN`, allowing the invalid candidate to pass the edge gate. - Infinity and out-of-range values can produce an arbitrarily large calculated edge and likewise pass the threshold. If market context contains no warnings and the program was invoked with `--live`, the invalid calculation reaches `client.trade`. ### Attack Path 1. The market API, an upstream provider, or a compromised dependency suppl ...[truncated 1131 chars]
Remediation
View remediation
float | None: try: probability = float(value) except (TypeError, ValueError, OverflowError): return None if not math.isfinite(probability): return None if not 0.0 <= probability <= 1.0: return None return probability ``` Reject invalid market records explicitly: ```python prob_yes = parse_probability(m.get("current_probability")) if prob_yes is None: print(f"Skip {question} (invalid current_probability)") continue ``` Additional hardening should include: 1. Require all environment-derived numeric settings to be finite and within documented bounds. 2. Require `trade_amount` to be positive and subject to a conservative maximum. 3. Require `scan_limit` to be a positive bounded integer. 4. Fail closed whenever market fields are missing, malformed, or semantically invalid. 5. Add tests for `NaN`, infinity, negative probabilities, probabilities above one, malformed strings, and missing values. 6. Apply account-level transaction limits and idempotency or duplicate-trade protections to constrain repeated live executions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares use of environment variables, including a required API key, but does not define an explicit tool/permission scope such as 'permissions' or 'allowed-tools'. This creates an avoidable trust gap: the runtime may grant broader access than readers or policy tooling can verify, increasing the risk of unintended secret exposure or capability creep if the skill is modified or interpreted permissively.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code reads SIMMER_API_KEY from the environment to authenticate trading actions, but there is no nearby comment, docstring, or user-facing message disclosing that the skill uses sensitive credentials. For code files, accessing sensitive environment variables should have some visible disclosure unless clearly documented elsewhere in the skill materials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.