Back to skill

Security audit

Polymarket Clob Microstructure

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed automated trading skill, but its live-trading safety controls are too weak for the financial authority it requests.

Review carefully before installing. Only run live mode with a constrained Simmer account, set conservative environment limits, and prefer a version that fails closed when safety context is unavailable, enforces per-trade and daily caps, and pins dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
clob_microstructure.py:28
Finding

Live Trading Proceeds When Safety Context Validation Fails

Content
View full analysis
0.15: return False, "slippage too high" edge = ctx.get("edge_analysis", {}) if edge.get("recommendation") == "HOLD": return False, "edge below threshold" return True, "ok" except Exception: return True, "context unavailable" ``` The returned value is subsequently used to authorize live execution: ```python ok, reason = check_context(client, sig["market_id"]) if not ok: log.warning("Skipping trade: %s", reason) continue if live: try: result = client.trade( market_id=sig["market_id"], side=side, amount=size, source=TRADE_SOURCE, skill_slug=SKILL_SLUG, reasoning=reasoning, ) ``` ### Technical Analysis `check_context()` is intended to prevent trades when flip-flop behavior, excessive slippage, or insufficient edge is detected. However, every exception raised while retrieving or parsing the context is converted into a successful authorization result: ```python return True, "context unavailable" ``` Consequently, network timeouts, authentication errors, SDK failures, malformed responses, unex ...[truncated 1706 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
clob_microstructure.py:74
Finding

Configured Trade Size Can Exceed the Declared Maximum Position Limit

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Security-Sensitive Third-Party Dependencies Are Unpinned

Content
View full analysis
Remediation
View remediation
", "requests==" ] ``` 2. Use a lock file with cryptographic hashes, or an installation mechanism equivalent to `pip --require-hashes`. 3. Retrieve packages only from a trusted and explicitly configured package index. 4. Review dependency provenance, release signatures, maintainers, and transitive dependencies. 5. Run automated vulnerability scanning against the complete resolved dependency graph. 6. Update dependencies through a controlled review process rather than resolving the latest versions during deployment. 7. Limit the process environment and filesystem permissions so imported packages receive only the minimum access needed. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.