Back to skill

Security audit

Polymarket API Guide

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Polymarket API guide that openly includes live trading, but it handles wallet keys and can place real orders with insufficient safeguards.

Install only if you intentionally want a skill that can guide or run live Polymarket trading code. Use a dedicated low-balance wallet, avoid giving it a primary private key, pin and review dependencies including py-clob-client, and require human confirmation or dry-run behavior before any order is placed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:4
Finding

Unpinned Dependencies Expose Security-Critical Trading Operations to Supply-Chain Risk

Content
View full analysis
=10.0 websocket-client>=1.0.0 python-socketio>=5.0.0 # HTTP clients aiohttp>=3.8.0 requests>=2.28.0 # Environment variables python-dotenv>=0.20.0 ``` The security-critical trading SDK is also installed without a version constraint and is not declared in `requirements.txt` or `skill.json`: ```python # lib/polymarket_client.py:10-13 Installation: pip install py-clob-client ``` ```python # lib/polymarket_client.py:69-71 if not PY_CLOB_CLIENT_AVAILABLE: raise ImportError( "py-clob-client is required for real trading. " "Install with: pip install py-clob-client" ) ``` The SDK receives wallet authority and is used to derive trading credentials: ```python # lib/polymarket_client.py:96-105 client = ClobClient( host="https://clob.polymarket.com", key=self.private_key, chain_id=137, # Polygon mainnet signature_type=self.signature_type ) # Derive API credentials from private key creds = client.derive_api_key() return client, creds ``` ### Technical Analysis All declared dependencies use open-ended lower bounds. A command such as `pip install -r requirements.txt` can therefore resolve to future package releases that were not reviewed with this Skill. There is no lock file, exact version pin, or package hash to ensure reproducible and integrity-verified installation. The more sensitive `py-clob-client` dependency is omitted from the formal dependency manifests and is instead installed through an unrestricted `pip install py-clob-client` instruction. This package is particularly security-critical because the application passes the user's wallet private key to its `ClobClient` object and relies ...[truncated 2306 chars]
Remediation
View remediation
websocket-client== python-socketio== aiohttp== requests== python-dotenv== py-clob-client== ``` 2. Add `py-clob-client` to both `requirements.txt` and `skill.json` so the security-critical dependency is visible, reproducible, and covered by dependency review. 3. Generate and verify package hashes using a locked requirements file, for example with `pip-compile --generate-hashes`, and install with: ```bash pip install --require-hashes -r requirements.lock ``` 4. Install dependencies in an isolated virtual environment under a non-privileged operating-system account. 5. Review the selected `py-clob-client` release and its transitive dependencies before allowing it to receive a production wallet key. Monitor package ownership and release-signing changes. 6. Use a dedicated, low-balance trading wallet with narrowly scoped approvals rather than a primary wallet. Keep private keys outside source code and avoid retaining them longer than necessary. 7. Establish a controlled dependency-update process that includes vulnerability scanning, source review for security-sensitive updates, automated tests, and explicit approval before changing locked versions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The supplied code chunk is narrowly scoped to order book retrieval and analysis using requests against the Polymarket data API. It includes utilities for summaries, depth visualization, liquidity checks, price impact estimation, and simple polling-based monitoring. The declared description, however, presents the skill as a broader Polymarket API/data access guide that includes connecting generally, finding markets, real-time WebSocket access, placing orders via the CLOB SDK, and understanding market mechanics. Those broader capabilities are not represented in this code chunk. While the order book portion does align with part of the description, the actual code materially under-delivers relative to the declared purpose, so this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents this as an API/data access guide, including WebSocket real-time data, order book access, and market mechanics. The supplied code is instead an operational client library for real trading: it accepts a private key, derives API credentials, queries wallet balance, and places FOK market orders through the Polymarket CLOB SDK. While some overlap exists around connecting to Polymarket, finding markets, and placing orders, the implemented behavior materially differs from the declared purpose and includes sensitive trading capabilities not reflected in the description. It also omits advertised features such as WebSocket streaming and order book access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata frames this as an API/data access guide, but this code initializes an authenticated trading client using a wallet private key and derives live API credentials. That mismatch is dangerous because a user or downstream agent may grant sensitive keys expecting read-only behavior, while the implementation enables real-money trading actions on Polymarket.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This method submits live orders to the Polymarket CLOB despite the skill being described as a learning/data access tool. In an agent setting, that context mismatch increases risk because automated consumers may invoke the skill assuming informational behavior, leading to unintended financial transactions and possible loss of funds.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill includes multiple concrete network interaction examples and endpoints, including HTTP requests and a live WebSocket connection, but the frontmatter does not declare any tool scope such as permissions or allowed-tools. In agent environments, that omission weakens policy enforcement and can lead to unintended outbound network access when the skill is used or adapted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill provides actionable instructions for authenticated order placement, including API credential setup and example order creation, but does not prominently warn about real-money loss, account exposure, irreversible trades, or misuse of private keys/API secrets. In an agent skill context, operational examples can be copied into live environments quickly, increasing the chance of unintended financial harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code performs live order placement immediately unless dry_run is manually set, with no built-in confirmation, warning, or policy guard. In an agentic environment this is especially risky because a single mistaken call, prompt injection chain, or parameter mix-up can trigger irreversible financial trades.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The docstring says this places a FOK market order, but the order arguments set expiration=0 with a comment indicating GTC, while the API call uses OrderType.FOK. This semantic inconsistency can cause operator misunderstanding, incorrect assumptions about execution guarantees, and potentially unintended order behavior depending on how the SDK interprets these fields.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section documents authenticated order placement and API key derivation but does not include any explicit warning that these actions can execute real trades, spend funds, and affect a user's account. In a skill intended to guide agent behavior, omission of such warnings increases the risk that an agent or user treats the examples as routine data access rather than financially impactful operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The function is documented as finding markets closing within a specified number of hours, but it compares a naive local datetime.now() value against timezone-aware UTC expiration timestamps parsed from the API. This does not reliably implement the stated behavior and can fail or behave incorrectly depending on runtime timezone handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring says this function is an async WebSocket example suitable for asyncio applications, but the implementation calls asyncio.wait_for and references asyncio.TimeoutError without importing asyncio anywhere in the module. This directly contradicts the documented intent because the advertised example will fail at runtime instead of providing the described async connection pattern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code initiates a network connection to an external service and sends a subscription payload, which is a safety-relevant operation under the rule. Unlike other parts of the file, this async example does not print or otherwise disclose the outbound connection/subscription action before it occurs, and the warning is only implicit in surrounding comments/docstrings.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with only a minimum version, which makes builds non-reproducible and can allow installation of unexpectedly vulnerable or breaking releases over time. In a networking-focused skill that uses WebSocket libraries, dependency drift increases supply-chain and patch-verification risk.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# Polymarket API Dependencies

# WebSocket support (multiple libraries for different use cases)
websockets>=10.0
websocket-client>=1.0.0
python-socketio>=5.0.0

Unverifiable Dependency: websockets has 4 known advisory(ies) (CVE-2018-1000518 (websockets is vulnerable to denial of service by memory exhaustion); CVE-2021-33880 (Observable Timing Discrepancy in aaugustin websockets library); CVE-2018-1000518 (aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly C) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest does not pin websockets, so it is impossible to verify whether deployed environments avoid known vulnerable releases. In a skill centered on WebSocket connectivity, that uncertainty directly affects a primary attack surface and can include denial-of-service or side-channel exposure depending on the resolved version.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using an unpinned websocket-client version means the installed package may vary by environment or over time, making security posture unverifiable and increasing exposure to supply-chain or regression issues. Because this skill is intended for API and real-time connectivity, this library is likely security-relevant runtime code.

Content

Scanner excerpt · requirements.txt (reported line 5)May include surrounding context.

text
# WebSocket support (multiple libraries for different use cases)
websockets>=10.0
websocket-client>=1.0.0
python-socketio>=5.0.0

# HTTP clients

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

python-socketio is unpinned, so consumers may resolve to different versions, including ones with serious known issues. Since this package handles network message parsing and session behavior, version ambiguity is more dangerous than for a purely local utility dependency.

Content

Scanner excerpt · requirements.txt (reported line 6)May include surrounding context.

text
# WebSocket support (multiple libraries for different use cases)
websockets>=10.0
websocket-client>=1.0.0
python-socketio>=5.0.0

# HTTP clients
aiohttp>=3.8.0

Unverifiable Dependency: python-socketio has 4 known advisory(ies) (CVE-2026-48804 (python-socketio: Binary attachment accumulation can cause denial of service); CVE-2025-61765 (python-socketio vulnerable to arbitrary Python code execution (RCE) through mali); CVE-2025-61765 (python-socketio vulnerable to arbitrary Python code execution (RCE) through mali) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

python-socketio has known advisories, including severe issues, and because no exact version is pinned there is no way to confirm that users will install a safe release. Given that this library processes inbound network data, unresolved version ambiguity can materially increase risk of remote compromise or denial of service.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

aiohttp is a core HTTP/networking library and leaving it unpinned makes the effective security baseline unknown across installations. This can expose users to vulnerable transitive behavior or incompatible releases without any code change in the skill itself.

Content

Scanner excerpt · requirements.txt (reported line 9)May include surrounding context.

text
python-socketio>=5.0.0

# HTTP clients
aiohttp>=3.8.0
requests>=2.28.0

# Environment variables

Unverifiable Dependency: aiohttp has 16 known advisory(ies) (CVE-2024-52303 (aiohttp has a memory leak when middleware is enabled when requesting a resource ); CVE-2026-54279 (aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence); CVE-2026-34514 (AIOHTTP has CRLF injection through multipart part content type header constructi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

aiohttp has a substantial advisory history, and without pinning the dependency the actual installed version cannot be assessed for exposure. Because it is an HTTP client/server framework with complex protocol handling, this uncertainty can affect request parsing, cookie handling, or resource exhaustion risks.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

requests is unpinned, so installs are not reproducible and may pull in versions with unresolved advisories or unexpected behavior changes. Although common, this is still a supply-chain hygiene issue that affects any code making outbound HTTP requests.

Content

Scanner excerpt · requirements.txt (reported line 10)May include surrounding context.

text
# HTTP clients
aiohttp>=3.8.0
requests>=2.28.0

# Environment variables
python-dotenv>=0.20.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

requests has multiple known advisories and the unpinned declaration prevents verification that installations avoid affected versions. Since the skill is an API integration guide, this dependency is likely to handle remote URLs, redirects, auth material, and transport settings, making insecure versions operationally relevant.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

python-dotenv is unpinned, creating uncertainty about which release is actually installed and whether it contains known flaws. Since this package handles environment configuration, unsafe versions could affect secrets handling or local file interactions.

Content

Scanner excerpt · requirements.txt (reported line 13)May include surrounding context.

text
requests>=2.28.0

# Environment variables
python-dotenv>=0.20.0

# Optional: For data processing and analysis
# Uncomment if you need these features:

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

python-dotenv has known advisories, and the lack of version pinning means consumers may install an affected build without visibility. While typically less exposed than network-facing libraries, it can still influence file writes, environment loading, and secret management behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/API_REFERENCE.md:146