Back to skill

Security audit

Polymarket Sports Live

Security checks for vulnerabilities and agentic risk

Overview

This skill is clearly a sports-trading automaton, but live mode can place repeated real-money trades with weak safety controls.

Review this carefully before installing. Use paper trading credentials and the default simulation venue unless you have added server-side trade limits, dependency pinning, fail-closed market-context checks, and explicit live-mode confirmation. Do not give it a key with more trading authority or funds than you are prepared to risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Unpinned Third-Party Dependencies Have Access to Trading Credentials

Content
View full analysis
Remediation
View remediation
requests== ``` 2. Generate and commit a lockfile containing transitive dependency versions. 3. Require cryptographic hashes during installation, such as with `pip install --require-hashes`. 4. Install packages only from an explicitly configured and trusted package index. 5. Verify that `simmer-sdk` is the official package and review its source and release provenance before deployment. 6. Use automated dependency scanning and controlled update review rather than accepting new releases automatically. 7. Restrict `SIMMER_API_KEY` server-side to the minimum required account, venue, transaction size, and trading permissions. 8. Use separate credentials for simulation and real trading, and rotate the credential if dependency compromise is suspected. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
sports_live.py:38
Finding

Pre-Trade Safety Validation Fails Open When Market Context Is Unavailable

Content
View full analysis
0.15: return False, "slippage too high" edge = ctx.get("edge_analysis", {}) if edge.get("recommendation") == "HOLD": return False, "edge below threshold" return True, "ok" except Exception: return True, "context unavailable" ``` The returned value authorizes the subsequent trade: ```python ok, reason = check_context(client, market_id) if not ok: log.warning("Skipping trade: %s", reason) continue if live: try: result = client.trade( market_id=market_id, side=side, amount=TRADE_SIZE_USD, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `check_context()` is intended to prevent trades when there is severe flip-flop activity, excessive slippage, or insufficient edge. However, every exception raised while retrieving or parsing the context is converted into `(True, "context unavailable")`. The caller interprets `True` as authorization to proceed. Therefore, network timeouts, authentication errors, malformed responses, SDK regressions, unexpected data types, o ...[truncated 1821 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares network and environment-variable capabilities but does not explicitly scope or constrain them with permissions or allowed-tools metadata. In an auto-executing trading skill, this increases risk because the runtime may grant broader access than necessary, making accidental secret exposure, unexpected outbound requests, or expanded behavior harder to review and contain.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The skill is designed to auto-execute on a cron schedule and can place real trades when run with live mode, which constitutes autonomous decision-making with financial impact. Even if not overtly malicious, unsupervised execution in a latency-sensitive trading context can amplify model errors, bad market matching, or malformed inputs into repeated financial losses before a human can intervene.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
## Scheduling

Runs every 2 minutes via cron (`*/2 * * * *`). Managed automaton (auto-executes on schedule).
Only trades when divergence exceeds 10%.

## Requirements

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill supports immediate real-money trading via the --live flag but does not present an explicit interactive confirmation or prominent warning before submitting orders. In the context of an automated sports-arbitrage trader, a user can easily trigger real trades by mistake or without fully appreciating that external live data and imperfect market matching may cause losses.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.