Back to skill

Security audit

Simmer Market Maker

Security checks for vulnerabilities and agentic risk

Overview

This real-money trading skill is mostly coherent, but live mode can cancel all open account orders before placing its own market-making quotes.

Review before installing. Use paper mode first, prefer a dedicated restricted API key or isolated account, avoid running --live if you have unrelated open orders, and pin or verify simmer-sdk before giving it access to trading credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Unpinned Third-Party Dependency Has Access to Trading Credentials and Operations

Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue, live=live) return _client ``` ### Technical Analysis The project instructs users and the Skill platform to install `simmer-sdk` without a fixed version or package-integrity hash. This permits the dependency resolver to install a future release whose contents may differ from the release reviewed with this Skill. The dependency executes inside the same Python process as the Skill. It is passed `SIMMER_API_KEY` directly and implements authenticated portfolio retrieval, position access, mark ...[truncated 1780 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
market_maker.py:206
Finding

Live Strategy Cancels All Account Orders Instead of Strategy-Owned Orders

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The skill invokes DELETE /api/sdk/orders without narrowing the operation to orders belonging to this strategy, market, or explicit user selection. This is a classic tool-parameter abuse pattern because a broad destructive API action is wired into normal execution flow, enabling accidental cancellation of all open account orders and potentially harming unrelated trading activity.

Content

Scanner excerpt · market_maker.py (reported line 207)May include surrounding context.

python
def cancel_open_orders(dry_run=True):
    """Cancel all existing open orders via DELETE /api/sdk/orders."""
    if dry_run:
        print("  [DRY RUN] Would cancel open orders")
        return True

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises behavior that requires environment access and networked trading/API interaction, but it does not declare any explicit tool scope or permissions boundary. That increases the chance an agent or user executes it with broader-than-necessary capabilities, reducing transparency and weakening least-privilege controls around access to API keys and outbound trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage instructions expose a simple '--live' path that can place real GTC orders and cancel existing orders, but they do not prominently warn that this can affect real funds and existing positions. In a trading skill, insufficient warning and confirmation around destructive financial actions materially increases the risk of accidental live execution and unintended losses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON manifest requires the environment variable SIMMER_API_KEY, which indicates the skill accesses a sensitive credential. The manifest does not include any descriptive warning or disclosure about credential use, data handling, or the implications of supplying this key.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Before placing strategy orders, the skill unconditionally cancels all open orders via a venue-wide DELETE endpoint. In a trading skill, this is dangerous because it can remove unrelated user orders across the account, causing loss of intended exposure, disruption of other strategies, and unintended financial consequences far beyond this skill’s stated scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The usage text advertises '--positions # Show positions', which suggests a complete position listing. The code later suppresses any position whose status is not 'active', so the documented behavior is broader than the actual output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill's stated purpose is to find markets and place passive limit orders, but the CLI also supports persisting configuration changes via --set and update_config(). That local configuration mutation is an ancillary management capability not justified by the manifest's trading-focused description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code updates and saves configuration to disk via update_config(), which is a file-write operation. Although it prints after saving, there is no prior warning, confirmation, or docstring/comment near the CLI action informing the user that --set will persistently modify local config state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.