Back to skill

Security audit

Polymarket AutoTrader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Polymarket auto-trader, but it can charge the user and place recurring real-money orders with a raw wallet key by default, and one trade path appears inconsistent with the documented strategy.

Review this carefully before installing. Use DRY_RUN=true first, do not use a wallet holding more funds or approvals than you are willing to risk, and avoid running it as a persistent service until the bearish trade logic, dependency pinning, and explicit consent controls for live orders and billing are addressed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
trader.js:78
Finding

Bearish Signals Submit SELL Orders Instead of Buying NO Tokens

Content
View full analysis
Remediation
View remediation
1) { throw new Error(`Invalid ask price for token ${tokenId}`); } const size = parseFloat(maxUsdc) / bestAsk; const order = await client.createAndPostOrder({ tokenID: tokenId, price: bestAsk, side: 'BUY', size, feeRateBps: 0, nonce: 0, expiration: 0, }); ``` Additional hardening should include: 1. Add unit tests asserting `BUY signal -> BUY YES` and `SELL signal -> BUY NO`. 2. Validate token ordering against explicit outcome labels rather than assuming array index zero is YES and index one is NO. 3. Reject missing, non-finite, zero, negative, or out-of-range prices instead of falling back to `0.5`. 4. Validate `MAX_TRADE_USDC` and enforce a positive upper bound before calculating order size. 5. Display the exact token outcome, exchange side, price, and maximum spend before submission. 6. Consider requiring explicit confirmation for the first live order after configuration changes. 7. Perform billing after preflight validation, or refund cycles where no documented operation can be attempted. ]]>

T08 · Insecure Dependencies

Warning
Location
package.json:9
Finding

Unpinned Dependencies and Missing Lockfile Make Wallet-Capable Builds Non-Reproducible

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill requests highly sensitive credentials, including a wallet private key and optional exchange API credentials, while also omitting declared permissions and embedding billing behavior not central to the headline description. In a trading skill, this is especially dangerous because misuse can directly lead to unauthorized market orders, financial loss, and compromise of blockchain wallet control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill requests highly sensitive credentials, including a wallet private key and optional exchange API credentials, while also omitting declared permissions and embedding billing behavior not central to the headline description. In a trading skill, this is especially dangerous because misuse can directly lead to unauthorized market orders, financial loss, and compromise of blockchain wallet control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill requests highly sensitive credentials, including a wallet private key and optional exchange API credentials, while also omitting declared permissions and embedding billing behavior not central to the headline description. In a trading skill, this is especially dangerous because misuse can directly lead to unauthorized market orders, financial loss, and compromise of blockchain wallet control.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements a complete billing and charging workflow that is unrelated to the stated purpose of automated Polymarket trading. A skill that can silently check balances, charge users, and generate payment links introduces monetization behavior that could be triggered without meaningful user awareness or necessity, making the skill materially more dangerous than advertised.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill submits live orders automatically via createAndPostOrder whenever billing passes and the generated signal exceeds the confidence threshold, without any interactive confirmation, explicit pre-trade acknowledgment, or protective approval gate. In an auto-trading skill that handles real wallet credentials and real-money markets, this makes accidental or unsafe execution materially more dangerous because a misconfiguration, bad signal, or unintended invocation can immediately place real trades.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares capabilities that require access to environment secrets and external network services, but it does not declare an explicit tool scope such as permissions or allowed-tools. In this context, the skill handles a wallet private key and billing credentials and is expected to contact Binance, Polymarket, and SkillPay, so missing scope boundaries increases the chance of overbroad execution and secret exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file accesses a secret API key from process.env and fails initialization if it is absent, solely to support external billing operations. For a skill described only as automated market trading based on RSI, MACD, and EMA signals, embedded billing credential handling is not an obvious or declared functional requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The chargeUser function can initiate a real billing action against a user account with no evidence of prior consent, confirmation step, or in-band disclosure. In the context of a trading skill, undisclosed charging is especially risky because users may reasonably assume actions relate only to market trades, not external account debits.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · strategy.js (reported line 8)May include surrounding context.

js
// ═══════════════════════════════════════════════════

// Binance public API for price data (no key needed)
const PRICE_API = 'https://api.binance.com/api/v3';

const SYMBOLS = {
  BTC: 'BTCUSDT',

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes an auto-trader that trades Polymarket markets based on technical signals. This code additionally charges the caller via SkillPay and blocks operation on insufficient balance, which is a separate monetization capability not justified by the stated trading function.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The required environment variables listed in the documentation do not fully align with the manifest metadata about billing-related credentials, which can cause users or orchestrators to misconfigure the skill. In a financial and billing context, configuration ambiguity is dangerous because it can lead to failed safeguards, accidental live execution, or unexpected charging behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file reads an API key from an environment variable and uses it in outbound HTTP requests, while also sending user identifiers to a third-party billing endpoint. There is no comment, docstring, logging, or other disclosure explaining this credential use or the associated network transmission.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret version range, which permits automatic installation of newer minor and patch releases. In an automated trading skill that can place real market orders and likely handles wallet credentials, a compromised or malicious upstream release could change runtime behavior or exfiltrate secrets without any code change in this repository.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"dry-run": "DRY_RUN=true node trader.js"
  },
  "dependencies": {
    "@polymarket/clob-client": "^3.9.0",
    "ethers": "^6.13.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The ethers package is also specified with a caret range, allowing unreviewed upstream updates to be pulled during installation. Because this skill is an auto-trader for Polymarket and likely signs transactions or manages private keys, dependency drift increases supply-chain risk and could directly lead to unauthorized trades or credential compromise.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
},
  "dependencies": {
    "@polymarket/clob-client": "^3.9.0",
    "ethers": "^6.13.0"
  }
}

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
billing.js:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trader.js:25