Back to skill

Security audit

Polymarket Candle Momentum

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Polymarket trading bot, but it needs Review because live mode can place real trades with underdocumented controls and a position-size setting that is not enforced as described.

Install only if you are comfortable with a script that can place real Polymarket trades when run with --live, especially under cron. Review and cap trade sizing yourself, pin dependencies, use a dedicated Simmer API key with the least possible account authority, and do not rely on CM_MAX_POSITION as a hard per-trade maximum without code changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
candle_momentum.py:351
Finding

Configured Maximum Position Is Not Enforced as a Hard Trade Limit

Content
View full analysis
= 0.85 and vol_surge >= 2.5: amount = min(base * 3.0, 15.0) # very strong: up to $15 elif body_ratio >= 0.75 and vol_surge >= 2.0: amount = base * 2.0 # strong: $10 elif body_ratio >= 0.65 and vol_surge >= 1.75: amount = base * 1.4 # medium: $7 else: amount = base # baseline: $5 ``` The resulting amount is submitted directly to the trading API: ```python result = client.trade( market_id=market_id, side=side, amount=amount, venue=os.environ.get("TRADING_VENUE", "polymarket"), source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=full_reasoning, ) ``` The conflicting documented setting appears in `SKILL.md:104`: ```markdown | `max_position` | 5.0 | `CM_MAX_POSITION` | Max USD per trade | ``` ### Technical Analysis A risk-control value described as a maximum must be enforced as a hard upper bound at the final transaction sink. Instead, `max_position` is used as a baseline for gradient sizing. With the default configuration of `$5`, qualifying signals can generate `$7`, `$10`, or `$15` trades. The first branch has a fixed `$15` cap, but the other multiplier branches have no independent upper bound. For example, a user-provided `CM_MAX_POSITION=100` could result in a `$200` trade in the second branch. No validation also ensures that the configured value is finite, positive, or within an account-level safety limit. The market context check does not restore the documented ma ...[truncated 1204 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Runtime Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
requests== ``` 2. Generate and commit a lock file containing cryptographic hashes, and install using hash verification: ```bash pip install --require-hashes -r requirements.txt ``` 3. Update `clawhub.json`, `SKILL.md`, and the runtime installation message so they all reference the same pinned dependency set. 4. Review dependency source code and release provenance before updating the lock file, especially for packages that receive credentials or execute trades. 5. Use automated vulnerability and dependency-change scanning, but require manual approval for SDK updates affecting authentication or transaction submission. 6. Run the Skill under a dedicated low-privilege operating-system account with access only to the required API key and network destinations, reducing the impact of a compromised package. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tainted flow: 'api_key' from os.environ.get (line 231, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · candle_momentum.py (reported line 232)May include surrounding context.

python
"""Find active fast markets for the configured asset via Simmer REST API."""
    try:
        api_key = os.environ.get("SIMMER_API_KEY", "")
        resp = requests.get(
            f"{SIMMER_API_BASE}/api/sdk/fast-markets",
            headers={"Authorization": f"Bearer {api_key}"},
            params={

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents capabilities that access environment variables and external networks, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent ecosystem, this weakens least-privilege enforcement and makes it easier for the skill to receive broader runtime capabilities than intended, especially since it can place live trades when invoked with --live.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The security notes claim only SIMMER_API_KEY is read from the environment, but the configuration section documents several additional environment variables that affect trading behavior. This mismatch undermines trust in the documentation and can cause reviewers or operators to underestimate the skill's external inputs, including parameters that control position sizing and execution thresholds.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
- Only `SIMMER_API_KEY` is read from environment. Nothing else.
- No host files are read. No logs written outside the script's own stdout.
- `automaton.managed` is `false` - the skill does not auto-execute.
- Dry-run by default. `--live` must be passed explicitly.

## Trade Execution Path

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation states there is no local file persistence, yet the CLI includes a --set KEY=VALUE command to update configuration state, which strongly implies some form of persistence or state mutation. This inconsistency can mislead operators about where sensitive trading parameters are stored and whether execution behavior can be changed outside ephemeral runtime state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code trades with source="sdk:polymarket-candle-momentum" but later queries positions with source="candle-momentum". This inconsistency can break tracking and monitoring, causing operators to miss active positions opened by the skill and make unsafe trading decisions based on incomplete state.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · candle_momentum.py (reported line 33)May include surrounding context.

python
TRADE_SOURCE = "sdk:polymarket-candle-momentum"
SKILL_SLUG = "polymarket-candle-momentum"

BINANCE_KLINES_URL = "https://api.binance.com/api/v3/klines"

ASSET_SYMBOLS = {
    "BTC": "BTCUSDT",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Running with --live can place real trades immediately without a final interactive confirmation or equivalent safety gate. In a trading skill, this materially increases the chance of accidental financial loss from operator error, automation misuse, or unexpected signal behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a fixed strategy scope over five assets, but the implementation includes DOGE, ADA, and AVAX in ASSET_SYMBOLS and supports overriding the target asset via configuration. This means the actual tradable universe is broader than the stated behavior, which is a semantic mismatch in the skill's advertised scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a trading strategy workflow, but the file also implements a --positions command that queries and displays current positions. Position inspection is not mentioned in the skill description and extends the observable behavior beyond the advertised strategy execution loop.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.