Back to skill

Security audit

Polymarket Command Center

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only Polymarket data helper with disclosed public API calls and optional local watchlist state.

Install only if you are comfortable with the skill making public HTTP requests to Polymarket and creating a local ~/.openclaw/state directory for watchlists. Consider asking the publisher to remove or update the unused pinned requests dependency and to add explicit permission metadata for the two Polymarket domains.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly describes live HTTP access to public Gamma and CLOB APIs but does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens security boundaries and user transparency, because a host may permit undeclared network activity or reviewers may underestimate the skill's external communication surface.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

md
|-------|----------|
| "Couldn't reach Polymarket" | Retry in 1 minute; check internet |
| "No markets found for..." | Try broader search term; check spelling |
| "No watchlist configured" | Add watchlist to config.yaml or create ~/.openclaw/state/polymarket_watchlist.json |
| Cached data looks stale | Cache TTL is 2 minutes; wait or restart service |
| CLOB midpoint missing | Market may not have CLOB tokens yet (new markets) |

Known Vulnerable Dependency: requests==2.32.5 — 2 advisory(ies): CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2026-25645 (Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract)

Medium
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is pinned to requests 2.32.5, and the supplied advisory indicates versions prior to 2.33.0 are affected by an insecure temporary file reuse issue in extract_zipped_paths(). Even in a read-only market data skill, shipping a known-vulnerable version is risky because vulnerable utility paths may still be reachable directly or indirectly by current or future code changes, and dependency-level flaws can become exploitable if attacker-controlled archives or paths are ever processed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/polymarket_commands.py (reported line 402)May include surrounding context.

python
"""Check odds on your watchlist markets."""
    slugs = WATCHLIST
    if not slugs:
        return "❌ No watchlist configured. Create ~/.openclaw/state/polymarket_watchlist.json with market slugs."

    lines = ["👀 Polymarket Watchlist", ""]

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes multiple curl examples to public Polymarket endpoints and later notes that requests must include a User-Agent header for logging/abuse detection. The document does not provide an explicit warning that using the skill or its examples will send request metadata to an external service, which is a privacy-relevant behavior for markdown under the missing-user-warnings rule.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and module docstring emphasize a read-only Polymarket interface, which accurately describes the network behavior, but the code also manages local state by creating ~/.openclaw/state and loading a watchlist from disk. That local filesystem statefulness is broader than a purely read-only browsing interface as described, even though it does not modify Polymarket data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.