Back to skill

Security audit

Polymarket Ai Divergence

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed trading skill, but it has material safety and scoping problems around API-key handling and live financial safeguards.

Install only if you are comfortable giving this skill a Simmer trading API key and reviewing its live-trading settings yourself. Keep it in dry-run until you verify the effective per-trade limit, daily budget, fee policy, and endpoint configuration; use a narrowly scoped revocable API key if possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/status.py:16
Finding

API Credential Can Be Redirected to an Arbitrary Network Host

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ai_divergence.py:346
Finding

Documented Zero-Fee Trading Safeguard Is Not Enforced

Content
View full analysis
0 else "no" edge = abs(div) # Subtract fee from edge — only trade if edge exceeds fee net_edge = edge - fee_pct if net_edge < MIN_EDGE: log(f" ⏭️ {question}... — edge {edge:.1%} - fee {fee_pct:.1%} = net {net_edge:.1%} < min {MIN_EDGE:.1%}") skip_reasons.append(f"net edge too low after {fee_rate_bps}bps fee") continue edge = net_edge # Use fee-adjusted edge for Kelly sizing ``` The declared behavior in `SKILL.md:88-96` states: ```markdown ### Fee Filtering 75% of Polymarket markets have 0% fees. The remaining 25% charge 10% (short-duration crypto/sports). This skill **only trades zero-fee markets** to avoid fee drag eroding the edge. ### Safeguards - **Fee check**: Skips markets with any taker fee ``` ### Technical Analysis The documentation represents zero-fee filtering as an unconditional safety control. The implementation does not reject nonzero fees. Instead, it subtracts the fee percentage from the calculated edge and proceeds whenever the remaining edge is at least `MIN_EDGE`. For example, a market with a 10% fee and a 20% reported divergence produces a 10% adjusted edge and remains eligible under the default 2% code threshold. This directly contradicts the advertised guarantee that any taker fee causes the market to be skipped. The code also defaults ...[truncated 1262 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Privileged Trading SDK Dependency Is Not Version or Integrity Pinned

Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue, live=live) return _client ``` ### Technical Analysis The package declaration requests `simmer-sdk` without an exact version, lockfile, or integrity hash. Installation can therefore resolve to a different package release over time. The dependency is security-sensitive because imported package code executes inside the Skill process and receives the Simmer API key. It also implements authenticated requests and transaction submission. A compromised package publisher, package-index account, distribution artifact, or unsafe future release would obtain the same environment and filesystem access as the Skill. No evidence in the reviewed files establishes that `simmer-sdk` is currently malicious. The vulnerability is the absence of dependency reproducibility and integrity controls around a privileged financial component. ### Attack Path 1. An attacker compromi ...[truncated 1113 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
clawhub.json:22
Finding

Managed Automation Defaults Exceed the Documented Trading Limits

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'req' from os.environ.get (line 30, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/status.py (reported line 34)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/markets",
            headers={"Authorization": f"Bearer {api_key}"}
        )
        data = json.loads(urlopen(req, timeout=30).read())
        markets = data.get("markets", [])
        
        high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior claims autonomous trade execution, Kelly sizing, fee filtering, and safeguards, while the analyzed implementation apparently does not perform those controls and is primarily status reporting. This mismatch is dangerous because users may rely on nonexistent protections or assume orders are being screened for risk when they are not, creating a serious operational and financial safety issue.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill describes use of network access, environment variables, and live trading flows, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can lead to broader-than-expected access and make it harder for operators to review or constrain what the skill is allowed to do before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes a command for live trade execution but does not present an explicit warning about financial loss, irreversible orders, or the need for user confirmation. In a trading context, that omission increases the chance of accidental real-money actions, especially when the documented interface makes switching from dry-run to live mode trivial.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest defines an automated trading skill but provides no activation conditions, trigger constraints, or contextual gating on when it should run. In a financial-trading context, unconstrained invocation increases the chance of unintended or excessive trade execution, especially if another component can invoke the skill opportunistically or without sufficient user intent checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The natural-language labels and environment names embed a specific currency/locale assumption (for example, 'USD', 'Max bet per trade', and 'Daily budget') without indicating that this is optional or region-specific. That can violate language/locale policy if the skill is presented generally rather than as a clearly US-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.