Back to skill

Security audit

Polymarket Real Estate Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed prediction-market trading skill that defaults to paper trading and only places live Polymarket trades when explicitly run with the live flag.

Install only if you are comfortable giving the skill a Simmer trading API key. It defaults to paper trading, but running it with --live can place real Polymarket orders, so review the position-size, spread, days-to-resolution, and max-position settings before enabling live mode.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.