Back to skill

Security audit

Decker + Polymarket

Security checks for vulnerabilities and agentic risk

Overview

This skill is for Polymarket trading through Decker, but it asks users to hand over a full wallet private key and sends an authentication secret in a URL for financially consequential requests.

Review carefully before installing. Use a dedicated low-balance wallet if you proceed, do not reuse a wallet that holds other assets, and treat any private key entered into Decker as exposed to that service. The skill should ideally use wallet-native signing or scoped, revocable credentials and require explicit confirmation before any trade request.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:36
Finding

Authentication Secret Exposed in a GET Request URL

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36–38
Vulnerability Type: Secret exposure through URL query parameters
Risk Level: High

Vulnerable Code

http
**Add exchange_id=polymarket to order-request**:

GET {DECKER_API_URL}/api/v1/link/slack/order-request?slack_user_id={sender_id}&symbol=will-x-win&side=buy&quantity=10&exchange_id=polymarket&outcome=yes&openclaw_secret={OPENCLAW_SECRET}

Technical Analysis

The documented request places OPENCLAW_SECRET directly in the query string of a GET request. Although HTTPS protects the URL while it is in transit, query strings are commonly retained by HTTP access logs, reverse proxies, API gateways, monitoring systems, debugging tools, browser history, and error-reporting platforms.

A secret embedded in a URL can therefore be disclosed to systems and personnel that do not require access to authentication credentials. This violates secure credential-handling and least-exposure principles. Because the endpoint submits a Polymarket order request, disclosure may expose an authentication capability associated with financially consequential operations.

Attack Path

  1. The agent constructs the documented GET request containing OPENCLAW_SECRET.
  2. The complete URL passes through the client, proxy, gateway, application server, or monitoring infrastructure.
  3. One or more components record the query string in logs or telemetry.
  4. An attacker or unauthorized operator obtains access to those records.
  5. The attacker extracts OPENCLAW_SECRET.
  6. The attacker reuses the secret against endpoints that accept it, subject to the credential's actual privileges and any additional authorization controls.

Impact Assessment

Successful exploitation could disclose an authentication secret and permit unauthorized requests under the affected user's or integration's identity. The precise scope depends on server-side authoriza ...[truncated 212 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the state-changing GET request with an HTTPS POST request.
  • Transmit credentials in an Authorization header, such as a short-lived bearer token, rather than in the URL.
  • Do not include secrets in query strings, path parameters, browser-visible links, or generated chat output.
  • Configure clients, gateways, application servers, and observability platforms to redact authorization data.
  • Use short-lived, narrowly scoped credentials restricted to the required operation, user, and exchange.
  • Add nonce, timestamp, expiration, and replay-prevention controls for financially consequential requests.
  • Require explicit user confirmation immediately before placing an order.
  • Rotate any OPENCLAW_SECRET that may already have appeared in URL logs and purge retained copies where feasible.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:54
Finding

Workflow Requires Export and Third-Party Submission of a Full Wallet Private Key

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54–59
Vulnerability Type: Excessive credential privilege and unsafe private-key handling
Risk Level: High

Vulnerable Code

text
1. Polygon wallet: Add the Polygon network in MetaMask (Chain ID 137)
2. Polymarket registration: Connect the wallet and deposit USDC.e for trading
3. Private-key export: MetaMask → Account Details → Export Private Key
4. Decker configuration: Sign in → Settings → Exchange API Settings → Polymarket
   - Secret Key: Polygon wallet private key beginning with 0x — required
5. Exchange selection: Set exchange_preference to "Polymarket" and save
6. Order: "Polymarket market-slug yes buy 10"

Technical Analysis

The instructions require the user to export the complete private key of a Polygon wallet and submit it to Decker as a mandatory secret. A wallet private key is not a narrowly scoped trading credential: it generally grants authority to sign arbitrary transactions for that wallet and cannot be constrained to one market, asset, order size, or API action.

This design breaks least-privilege boundaries by transferring broad wallet authority to a third-party service. A warning not to share the key does not mitigate the risk because the preceding workflow explicitly requires providing that key to the service. Any compromise of the user's Decker account, a deceptive interface, service-side storage, operational access, or downstream credential processing could expose the key.

Attack Path

  1. The user follows the Skill instructions and exports the Polygon wallet private key from MetaMask.
  2. The user enters the private key into the Decker configuration interface.
  3. The key is transmitted to and processed by infrastructure outside the local wallet.
  4. An attacker compromises the user's service account, impersonates the configuration interface, obtains unauthorized infrastructure access, or accesses improperly prot ...[truncated 988 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all instructions that require exporting or uploading a wallet private key.
  • Use wallet-native connection and signing protocols that keep the private key inside MetaMask or another trusted wallet.
  • Require explicit, human-readable confirmation for each transaction or authorization request.
  • Where supported, use delegated or session keys with strict limits on market, contract, asset, amount, duration, and permitted actions.
  • Separate trading funds from other assets by using a dedicated low-balance wallet.
  • Document credential custody, storage, encryption, retention, revocation, and incident-response procedures.
  • Protect any unavoidable signing service with hardware-backed key storage, strict access controls, audit logging, and transaction policy enforcement.
  • Advise users who previously submitted a raw key to migrate assets to a newly generated wallet, revoke token approvals, and discontinue use of the exposed key.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the user to export a Polygon wallet private key from MetaMask and enter it into another service as a 'Secret Key.' Encouraging collection and reuse of a wallet private key in a third-party service is highly dangerous because compromise of that service, logs, prompts, or user error could expose the key and allow complete theft of wallet assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill enables market buys on a real prediction market and gives concrete order syntax, but it does not require a clear confirmation flow or prominently warn that orders can spend real funds and create irreversible financial exposure. In a trading context, that omission increases the chance of accidental or uninformed transactions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
## 참고

- 메인 decker 스킬: `docs/openclaw_skills/decker/SKILL.md`
- Polymarket: 예측시장 (YES/NO 이진 시장)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language instructions and invocation examples are predominantly Korean, which can imply a language-specific interaction mode. The file does not state that the skill is intentionally Korea-targeted or offer users an explicit language/locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.