Back to skill

Security audit

Polymarket Trading Setup

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Polymarket trading setup guide, but it asks agents to handle real wallet keys, persist trading credentials in plaintext, and place live orders with limited safeguards.

Review carefully before installing. Use a dedicated low-balance wallet, prefer a secret manager or encrypted environment over project-local `.env`, never commit credentials, pin and lock dependencies, and require explicit approval before any live order or token approval is submitted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:80
Finding

Unpinned Third-Party Dependencies Execute in a Credential-Bearing Trading Environment

Content
View full analysis
=0.28.0" httpx "websocket-client>=1.9.0" orjson pandas python-dotenv ``` `GUIDE.md:1010`: ```bash pip install "py-clob-client>=0.28.0" httpx "websocket-client>=1.9.0" orjson pandas python-dotenv ``` ### Technical Analysis The installation instructions leave `httpx`, `orjson`, `pandas`, and `python-dotenv` entirely unpinned. The constraints for `py-clob-client` and `websocket-client` only specify minimum versions and therefore also permit unreviewed future releases. Python packages and their installation hooks execute code in the local environment. In this Skill, that environment is expected to contain `POLYMARKET_PRIVATE_KEY`, CLOB API credentials, Builder API credentials, and authority to submit financial orders. Consequently, dependency integrity is a critical security boundary. The project provides no lockfile, package hashes, trusted-index restriction, or reproducible dependency manifest. This does not establish that any currently named package is malicious, but it permits a compromised or unexpectedly changed future release to be installed without further review. ### Attack Path 1. An attacker compromises a permitted package release or its publishing account. 2. A user or Agent follows the documented `pip install` command. 3. Package installation or import executes attacker-controlled Python code. 4. The malicious code reads environment variables or plaintext `.env` files containing wallet and API credentials. 5. The code exfiltrates those credentials, changes contract or API destinations, manipulates signed orders, or directly invokes available trading APIs. 6. The attacker uses the exposed authority to submit unauthorized orders or otherwise compromise the trading account. ### Impact Assess ...[truncated 687 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:59
Finding

Wallet Private Key and Trading API Credentials Are Persisted in Plaintext Environment Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This section tells users to persist derived API credentials to .env or config, which promotes long-lived local storage of secrets without accompanying controls. If those secrets are exposed through repo commits, backups, CI logs, or host compromise, an attacker could authenticate to the user's Polymarket account and interact with private trading functionality.

Content

Scanner excerpt · GUIDE.md (reported line 161)May include surrounding context.

else: api_creds = client.derive_api_key() client.set_api_creds(api_creds) # Persist to .env or config

text

### WebSocket Authentication

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The checklist again directs users to write derived credentials into a .env file, reinforcing insecure secret-handling practices in a context involving financial trading access. Because this skill is specifically for automated trading, leaked credentials may expose account activity, position data, and potentially enable unauthorized order actions depending on platform permissions.

Content

Scanner excerpt · GUIDE.md (reported line 1049)May include surrounding context.

funder="0x...", ) creds = client.derive_api_key()

Write to .env — do not log or print credentials

text
- [ ] **Add credentials to your `.env` file:**
```bash

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

funder=os.getenv("POLYMARKET_PROXY_ADDRESS"), ) creds = client.derive_api_key()

Write credentials to .env — do not log or print them

text

Add to `.env`:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs users to store Polymarket API key material in a .env file but does not explicitly warn that these credentials are sensitive secrets that must be kept out of source control and protected on disk. In an agent/developer workflow, .env files are commonly committed accidentally, copied into logs, or included in support bundles, which could expose trading credentials and enable unauthorized account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide recommends placing a live test order without clearly warning that Polymarket orders use real funds and may create real positions, partial fills, fees, or losses. In a trading automation skill, users may treat this as a harmless connectivity test and unintentionally execute financial transactions on production markets.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
GUIDE.md:127