Back to skill

Security audit

Polymarket Market Importer

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate market-import automation skill, with normal caution needed because it uses a Simmer API key and can make live account changes when enabled.

Install only if you intend to let this skill access your Simmer account and import markets. Run the default dry run first, keep max_per_run conservative, confirm whether any schedule is enabled for live mode, and prefer a scoped API key plus a pinned or reviewed simmer-sdk version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unpinned Third-Party Dependency Receives a Live API Key

Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "polymarket") _client = SimmerClient(api_key=api_key, venue=venue, live=live) ``` ### Technical Analysis The project declares and recommends installing `simmer-sdk` without an exact version, package hash, lockfile, or verified source constraint. Package resolution can therefore select different releases over time. Python executes the dependency during import, and the application subsequently passes `SIMMER_API_KEY` to dependency-controlled code. This creates a supply-chain trust boundary: the reviewed project does not control the code that handles the credential, performs network requests, loads and updates configuration, and initiates live market imports. A compromised, malicious, or unexpectedly changed future package release could execute arbitrary Python code with the same operating-system privileges as the Skill. The audit found no evidence that the current dependency is malicious. Exploitation depends on compromise, replac ...[truncated 1645 chars]
Remediation
View remediation
"] ``` ```bash pip install simmer-sdk== ``` 2. Generate and commit a dependency lockfile containing cryptographic hashes. Install with hash verification, such as: ```bash pip install --require-hashes -r requirements.txt ``` 3. Obtain packages only from an explicitly configured and trusted package index. Disable unintended fallback indexes to reduce dependency-confusion risk. 4. Review the selected package release and its transitive dependencies before updating the pin. Use automated dependency scanning and require controlled review for version changes. 5. Run the Skill under a dedicated, least-privileged operating-system account or sandbox. Restrict filesystem access and outbound network destinations to those required for Simmer operations. 6. Scope `SIMMER_API_KEY` to the minimum necessary permissions and quota. Avoid exposing unrelated credentials to the process environment. 7. Rotate the API key if an untrusted or unverifiable dependency version has previously been installed or executed. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation indicates capabilities involving environment access and file writing, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where an agent or platform may grant broader access than users expect, increasing the risk of unintended secret exposure or filesystem modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description emphasizes scheduled automation but does not warn that unattended recurring execution may continue performing live imports without user review. In the context of a market-importing skill tied to an account API key, this raises the chance of repeated unintended state changes, quota exhaustion, and accumulation of unwanted imported markets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README presents --live as a normal operational mode but does not clearly warn that it will perform real imports into Simmer and modify account state. Users may run the command assuming it is informational, which can lead to unintended account changes, quota consumption, or automated trading workflow side effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.