Back to skill

Security audit

polymarket-minimal-buy-python

Security checks for vulnerabilities and agentic risk

Overview

This is a real Polymarket trading skill, but it asks for a raw wallet private key and can make live financial changes without strong safeguards.

Review this carefully before installing. Only use a dedicated low-balance trading wallet, do not paste a primary wallet private key into private.env, keep any secret file out of git and backups with restrictive permissions, and avoid running live order or cancel-all commands unless you understand the exact market, amount, approvals, and consequences.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

Wallet Private Key Stored in an Unprotected Plaintext Environment File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-28, SKILL.md:37-43, scripts/min_buy.py:30-39, and scripts/min_buy.py:199-203
Vulnerability Type: Plaintext storage and unsafe loading of sensitive credentials
Risk Level: Medium

Vulnerable Code

SKILL.md:23-28:

bash
# Auto-create private.env if it does not exist
test -f private.env || cat > private.env <<'EOF'
POLYMARKET_PRIVATE_KEY=
EOF

echo "Created private.env if it was missing. Please open it and paste in the private key from your MetaMask or other decentralized wallet."

SKILL.md:37-43:

markdown
* `POLYMARKET_PRIVATE_KEY` (required)

Example:

```env
POLYMARKET_PRIVATE_KEY=your_wallet_private_key
text

`scripts/min_buy.py:30-39`:

```python
def load_env_file(path: Path) -> None:
    if not path.exists():
        return
    for raw in path.read_text(encoding="utf-8").splitlines():
        line = raw.strip()
        if not line or line.startswith("#") or "=" not in line:
            continue
        key, value = line.split("=", 1)
        os.environ[key.strip()] = value.strip().strip('"').strip("'")

scripts/min_buy.py:199-203:

python
args = parse_args()
load_env_file(Path(args.env_file))

private_key = getenv_required("POLYMARKET_PRIVATE_KEY")
trader = SimplePolymarketTrader(private_key)

Technical Analysis

The documented setup directs users to store a complete EVM wallet private key in a plaintext private.env file. The file is created using the process's default permission behavior and is not explicitly restricted to the owning user. The project also does not include documented protection against committing the file to source control.

The environment-file parser accepts an arbitrary path supplied through --env-file, reads all assignments from that file, and copies them into the process environment. It does not validate file ownership, reject symbolic ...[truncated 1609 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an operating-system keychain, hardware wallet, or managed secret store instead of a plaintext project file.

  2. Use a dedicated, low-value trading wallet rather than a primary wallet containing unrelated assets.

  3. If file-based storage remains supported, create the file securely:

    bash
    umask 077
    install -m 600 /dev/null private.env
    printf '%s\n' 'POLYMARKET_PRIVATE_KEY=' > private.env
    
  4. Before loading the file, reject symbolic links, verify that it is owned by the current user, and require permissions no broader than 0600.

  5. Parse only POLYMARKET_PRIVATE_KEY rather than copying every assignment into os.environ.

  6. Add private.env to .gitignore and provide a non-sensitive private.env.example template.

  7. Document that exposed keys must be considered permanently compromised. Users should move assets to a new wallet and revoke existing approvals rather than merely editing the file.

  8. Avoid printing the key in errors, logs, shell history, debugging output, or process arguments.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Security-Critical Python Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:20:

bash
pip install py-clob-client eth-account

Technical Analysis

The installation command resolves the latest available versions of py-clob-client, eth-account, and their transitive dependencies at installation time. It provides neither exact version constraints nor package hashes.

These dependencies execute in the same Python process that receives the wallet private key. In particular, the script passes the private key into Account.from_key() and ClobClient. A malicious, compromised, or unexpectedly changed dependency release could therefore read the private key, alter signed order data, redirect network requests, or execute arbitrary code with the user's operating-system privileges.

No evidence was found that either named package is currently malicious. The vulnerability is the absence of reproducible dependency and integrity controls around security-critical signing code.

Attack Path

  1. A user runs the documented pip install py-clob-client eth-account command.
  2. The package index resolves versions available at that time rather than versions reviewed with this project.
  3. A compromised upstream account, malicious release, package-index incident, or unsafe transitive dependency supplies attacker-controlled code.
  4. Package installation hooks may execute immediately with the user's privileges.
  5. At runtime, imported dependency code executes inside the trading client process.
  6. The dependency can access signing inputs, including the wallet private key, or modify order construction and network behavior.
  7. The attacker may exfiltrate credentials, submit altered orders, or execute other commands available to the user's account.

Impact Assessment

Exploitation could provide arbitrary code execution wit ...[truncated 570 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin reviewed direct and transitive dependency versions in a lockfile.

  2. Require package hashes, for example through a generated requirements file used with:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Install dependencies inside a dedicated virtual environment using a non-privileged account; never run the installation command with sudo.

  4. Review release notes and security advisories before updating signing or blockchain-related packages.

  5. Use automated dependency scanning and periodically regenerate pins after controlled review and testing.

  6. Configure installation to use the official package index or an authenticated internal mirror rather than untrusted indexes.

  7. Consider verifying downloaded artifacts and maintaining a software bill of materials for reproducible audits.

  8. Isolate the trading process and use a dedicated wallet with limited funds to reduce the consequences of dependency compromise.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs users to place a raw wallet private key into a local file for authenticated trading, but does not provide strong warnings or safeguards about the sensitivity of that credential. Wallet private keys grant full control over funds, so storing them in a plaintext file materially increases the risk of theft through accidental disclosure, local compromise, backups, logs, or misuse by other tools.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the user to store a wallet private key in private.env so the tool can read and use it for authenticated operations. This is dangerous because a raw blockchain private key is a highly sensitive secret that enables irreversible asset transfers, and placing it in a plaintext local file broadens the attack surface to malware, shell history, backups, misconfigured permissions, and accidental disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The setup and examples repeatedly tell the user to paste their wallet private key into private.env, normalizing unsafe secret handling and increasing the chance the key will be stored insecurely or reused in an unsafe workflow. In the context of a live trading client, compromise of this key could directly lead to unauthorized trades or theft of on-chain assets.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The suggested prompt text directly asks the user to populate an environment variable with a private key from MetaMask or another wallet, which encourages extraction of the user's master signing credential from its safer native context into general-purpose local storage. This makes the skill more dangerous because it explicitly operationalizes the transfer of a high-impact secret into a format easily read by scripts and other local processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document describes methods for market/limit buy and sell orders, token allowance approvals, and order cancellation, but it omits any user warning that these actions can move funds, grant spending permissions, or alter open positions. In the context of an executable trading skill, this makes the behavior materially more dangerous because a user may invoke powerful financial operations without understanding the consequences or required confirmations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cancel_all() command performs bulk cancellation of market orders with no warning, scoping confirmation, or preview of affected orders. In an automated trading context this is more dangerous than a single-order action because a mistaken or malicious invocation can instantly disrupt all active strategy state, potentially causing missed fills, forced exposure, or operational loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs the reader to load a Polymarket private key from a local environment file and use it for wallet initialization and API credential derivation, but it provides no warning about the sensitivity of that secret or the risks of mishandling it. In a trading skill, this omission is security-relevant because private key exposure can lead to full wallet compromise and unauthorized trading activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code automatically calls update_balance_allowance() whenever no current allowance is detected, which performs a live blockchain authorization write without any explicit user confirmation or dry-run step. In a trading skill that loads a private key and executes real transactions, this can silently grant spending permissions and expose funds to unintended approvals if the operator misunderstands the command or the environment is misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The market and limit order paths submit live buy/sell orders immediately with no runtime warning, confirmation prompt, or safe simulation mode. Because this script is a minimal trading client wired to a real private key and production host, accidental invocation, bad parameters, or misuse by an upstream agent can directly cause financial loss through unintended trades.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.