Back to skill

Security audit

Polymarket

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly for Polymarket trading, but its setup directs users to run an unverified remote installer before using wallet and real-money trading features.

Install only if you intend to use an agent for real-money Polymarket activity. Use the read-only features without installing the CLI when possible. Do not run the documented curl-to-sh installer as written; prefer a pinned, verified release or manually reviewed installer, and keep any wallet used here limited to funds you are prepared to risk.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:31
Finding

Unverified Remote Installer Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31, with the same instruction duplicated at README.md:37 and printed by scripts/polymarket.py:49
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippets

SKILL.md:31:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

README.md:37:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

scripts/polymarket.py:49:

python
print("   Install: curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh", file=sys.stderr)

Technical Analysis

The installation command downloads install.sh from the mutable main branch of an external GitHub repository and immediately passes the response to sh. The effective code executed on a user's system can therefore change after this Skill has been reviewed.

The command provides no immutable commit pin, release-version pin, checksum validation, cryptographic signature verification, or local inspection step. The -L option also follows redirects, so the shell executes the final response body without confirming that it came from the originally displayed location.

The URL belongs to the declared Polymarket project and installing its CLI is relevant to the Skill's trading features. However, immediate execution of mutable network content is not the minimum privilege or minimum-risk mechanism needed to install that dependency. The read-only features do not require the CLI at all, while trading users could install a pinned, verified release artifact instead.

The Python program does not itself execute this installation string; it prints the instruction when the CLI is missing. Nevertheless, both the Skill instructions and the program direct the user or agent toward the unsafe execution pattern.

Attack Path

  1. An attacker compromises the upstream repository, a main ...[truncated 1801 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove every instruction that pipes a network response directly into a shell, including the copies in SKILL.md, README.md, and scripts/polymarket.py.
  2. Pin the dependency to a reviewed release version or immutable commit rather than the mutable main branch.
  3. Prefer an official package manager or a signed release artifact from the upstream publisher.
  4. Download the artifact to disk before execution so that its origin, contents, and expected filename can be reviewed.
  5. Publish and verify a SHA-256 checksum obtained through a trusted, independently protected channel.
  6. Verify a cryptographic signature where upstream signing is available.
  7. Fail closed on download errors by using curl -f, and avoid executing responses that may be error pages or unexpected redirected content.
  8. Keep installation separate from ordinary Skill execution and require explicit user approval.
  9. Document that read-only functionality does not require installation, limiting exposure to users who explicitly need trading features.

A safer installation pattern would resemble:

bash
curl -fL \
  -o polymarket-install.sh \
  "https://raw.githubusercontent.com/Polymarket/polymarket-cli/<immutable-commit>/install.sh"

echo "<trusted-sha256>  polymarket-install.sh" | sha256sum -c -
less polymarket-install.sh
sh polymarket-install.sh

For stronger hardening, replace the installer script with a pinned release binary and verify both its publisher signature and checksum before installation.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (10)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping curl output directly into sh creates an immediate command-execution chain with no review barrier, which is especially risky in a skill that later manages a real-money wallet and private keys. If the fetched content is tampered with, an attacker could execute arbitrary code, steal wallet material, alter trades, or compromise the host environment.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

  1. Install the Polymarket CLI:

    bash
    curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh
    
  2. Set up a wallet:

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of a shell pipeline into sh removes any opportunity for inspection before execution and creates a direct command-execution chain from network input to the local shell. In this skill's context, that is especially risky because the same skill handles wallet configuration and real-money trading, so a malicious installer could steal keys, alter trades, or persist on the system.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

For trading, order books, and price history, install the Polymarket CLI:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

For trading, set up a wallet:

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · scripts/polymarket.py (reported line 337)May include surrounding context.

python
cli = require_cli()
    print("🔧 **Wallet Setup**")
    print("Running interactive setup. This will guide you through wallet creation.\n")
    os.execvp(cli, [cli, "setup"])


def cmd_wallet_show(args):

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

  1. Set up a wallet:
    text
    polymarket wallet create
    polymarket approve set
    

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises shell and network-capable workflows but does not declare any explicit tool scope or permissions boundary. In an agent environment, this increases the chance the skill can trigger command execution or network access without clear user/admin review, making risky operations like installs, wallet setup, and trading easier to invoke unintentionally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill expands from API querying into local execution of an external CLI for trading and wallet operations, which increases the trust boundary substantially. In an agent-skill context, invoking locally installed binaries can expose wallets, credentials, and trading capability, especially because this script assumes the external CLI is safe and authentic.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/polymarket.py (reported line 61)May include surrounding context.

python
if json_output:
        cmd += ["-o", "json"]
    cmd += args
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
    if result.returncode != 0:
        err = result.stderr.strip() or result.stdout.strip()
        print(f"❌ CLI error: {err}", file=sys.stderr)

External Script Fetching

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The README instructs users to fetch and execute a remote install script directly from GitHub with curl | sh. This is dangerous because any compromise of the GitHub account, repository, branch, CDN path, or network trust chain could cause arbitrary shell commands to run on the user's machine immediately.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

  1. Install the Polymarket CLI:

    bash
    curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh
    
  2. Set up a wallet:

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to download and execute a remote install script directly from GitHub using curl piped into sh. This is dangerous because any compromise of the remote repository, branch, CDN path, or transport context would result in immediate arbitrary code execution on the host running the skill.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

For trading, order books, and price history, install the Polymarket CLI:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

For trading, set up a wallet:

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Printing a shell-pipe installer command that fetches and executes a remote script encourages unsafe installation of unverified code. In a security-sensitive trading skill, this is more dangerous because the installed CLI may handle wallet setup and real-money transactions, so compromise of the remote script or repository could lead to credential theft or fund loss.

Content

Scanner excerpt · scripts/polymarket.py (reported line 49)May include surrounding context.

python
cli = find_polymarket_cli()
    if not cli:
        print("❌ Polymarket CLI not installed. Trading commands require it.", file=sys.stderr)
        print("   Install: curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh", file=sys.stderr)
        sys.exit(1)
    return cli

Static analysis

No suspicious patterns detected.