Back to skill

Security audit

Polymarket Fast Loop Improved

Security checks for vulnerabilities and agentic risk

Overview

This skill is for live automated trading, but the reviewed package does not include the trading script while still recommending persistent live cron execution.

Review this before installing. Do not run the live or cron examples unless you have independently obtained and audited the missing fastloop_improved.py file, pinned and verified dependencies, and configured a narrowly scoped, revocable trading key with external spend and loss limits.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:59
Finding

Persistent Unattended Live-Trading Jobs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:38
Finding

Unpinned Third-Party Trading Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:43
Finding

Security-Critical Trading Entrypoint Is Missing from the Audited Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.