Back to skill

Security audit

Polymarket Copytrading

Security checks for vulnerabilities and agentic risk

Overview

This is a real copy-trading skill with live financial authority, but its selling behavior and trade-safety boundaries are not disclosed or enforced clearly enough.

Install only if you are comfortable giving this skill authority over a low-value, tightly limited trading account. Use dry-run first, prefer $SIM paper trading, avoid exposing a broad wallet private key, and do not rely on the documentation's 'buy only' wording unless you explicitly disable whale exits with --no-whale-exits and verify behavior before using --live.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
copytrading_trader.py:238
Finding

Server-generated trade plans execute without local policy enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:89
Finding

Documentation conceals default whale-exit selling behavior and references a nonexistent option

Content
View full analysis
**By default, only buys execute.** Pass `--rebalance` to also sell positions the whales have exited, or `--whale-exits` to sell only on whale exits. ``` ```markdown **Sell when whales exit positions:** ```bash python copytrading_trader.py --whale-exits ``` ``` ### Implemented Behavior ```python parser.add_argument( "--rebalance", action="store_true", help="Full rebalance mode: buy AND sell to match targets (default: buy-only)" ) parser.add_argument( "--no-whale-exits", action="store_true", help="Disable whale exit detection (default: whale exits are detected and sold)" ) ``` ```python run_copytrading( wallets=wallets, top_n=top_n, max_usd=max_usd, dry_run=dry_run, buy_only=not args.rebalance, detect_whale_exits=not args.no_whale_exits, venue=venue ) ``` ### Technical Analysis The documentation says that only purchases execute by default and instructs users to enable exit selling with `--whale-exits`. That option does not exist in the argument parser. The actual implementation enables whale-exit detection by default: ```python detect_whale_exits = not args.no_whale_exits ``` Consequently, a user must specify `--no-whale-exits` to disable exit-triggered sales. The phrase “buy-only” is therefore ambiguous and materially understates the default authority granted to the remote trade planner. This is security-relevant because selling an existing financial position is materially different from declining to make further purchases. The discrepancy undermines informed consent for live financial operations. ### Attack Path 1. A user reads `SKILL.md` and concludes that the default mode ...[truncated 1135 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded third-party SDK dependency handles API credentials, wallet signing, and trades

Content
View full analysis
=0.9.19 ``` The dependency is imported and receives trading credentials in `copytrading_trader.py:79-93`: ```python def get_client(): """Lazy-init SimmerClient singleton.""" global _client if _client is None: try: from simmer_sdk import SimmerClient except ImportError: print("Error: simmer-sdk not installed. Run: pip install simmer-sdk") sys.exit(1) api_key = os.environ.get("SIMMER_API_KEY") if not api_key: print("Error: SIMMER_API_KEY environment variable not set") print("Get your API key from: simmer.markets/dashboard -> SDK tab") sys.exit(1) venue = _config.get("venue") or os.environ.get("TRADING_VENUE") or "polymarket" _client = SimmerClient(api_key=api_key, venue=venue) return _client ``` The documentation also states that the SDK may use a private signing key in `SKILL.md:281-286`: ```markdown **"External wallet requires a pre-signed order"** - `WALLET_PRIVATE_KEY` is not set in the environment - The SDK signs orders automatically when this env var is present — no manual signing code needed - Fix: `export WALLET_PRIVATE_KEY=0x` - Do NOT attempt to sign orders manually or modify the skill code — the SDK handles it ``` ### Technical Analysis The version constraint `>=0.9.19` allows package installation to resolve to any later release. Therefore, the code that is actually installed and executed may differ from the dependency version originally reviewed. This is especially sensitive because `simmer-sdk`: - Receives `SIMMER_API_KEY`. - Performs authenticated network requests. - Submits financial trades. - Is documented as automatically signing orders when `WALLET_PRIVATE_KEY` is pres ...[truncated 1844 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation describes automated copytrading, wallet aggregation, and trade execution, but the detected behavior is read-only portfolio and position inspection. This mismatch is dangerous because operators may grant higher trust, permissions, or financial authority based on the stated purpose, while the actual implementation does something materially different, undermining reviewability and creating room for future bait-and-switch changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest requires a SIMMER_API_KEY for copy-trading but provides no user-facing warning that the skill can initiate financially impactful actions using that credential. Because the skill mirrors external wallets and sizes trades automatically, users may supply a sensitive credential without understanding that it enables live market activity and potential financial loss.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises commands that rely on environment-backed secrets and trading capability, but it does not declare an explicit tool scope such as allowed tools or permissions. That creates an authorization ambiguity: an agent or runtime may expose environment access more broadly than intended, increasing the chance of secret access or unintended trading-related execution paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest declares a managed automaton entrypoint for an automated copy-trading skill, but it does not define clear invocation constraints, trigger scope, or user-consent boundaries. In a financial trading context, unconstrained automation materially increases the chance of unintended trade execution, repeated runs, or operation under conditions the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower-bound only version constraint, which allows installation of any newer release of simmer-sdk, including unreviewed or potentially compromised versions. In a trading-related skill that interacts with external APIs and may influence financial actions, supply-chain compromise or breaking changes in a future package release could materially affect behavior and integrity.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
simmer-sdk>=0.9.19

Static analysis

No suspicious patterns detected.