Back to skill

Security audit

polymarket-paper-trader

Security checks for vulnerabilities and agentic risk

Overview

This paper-trading skill is mostly coherent, but it gives the agent autonomous local trading behavior and includes an ambiguous instruction to post leaderboard data through the user's GitHub CLI.

Install only if you are comfortable with an agent autonomously making paper trades and maintaining local trading history. Before allowing leaderboard or social-sharing workflows, require confirmation, especially for any action that would use your GitHub CLI or post public content. Consider pinning the package version before installation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run uvx --from polymarket-paper-trader pm-trader-mcp without pinning an exact version or immutable source. That creates a supply-chain risk: a future compromised or malicious package release could be pulled and executed automatically by the agent environment, leading to arbitrary code execution during install or runtime startup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill tells the agent 'When you're activated for the first time, do this' and later says 'Don't ask ... — trade', but it does not define a narrow, explicit activation trigger or require user confirmation. In an agent ecosystem, this can cause autonomous side effects on invocation, including account initialization, trading actions, and content generation without clear consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The phrase "uses public Polymarket API only (read-only)" suggests a read-only overall capability. However, the documented toolset includes write-like behaviors unrelated to merely reading Polymarket data, including buy/sell simulation, resetting accounts, generating leaderboard submissions, and content intended for external posting; this contradicts the stated intent of being purely read-only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that data 'stays local' and is 'never uploaded', but elsewhere the skill explicitly encourages generating shareable cards, posting to X, and submitting leaderboard data externally. This mismatch can mislead users about privacy boundaries and cause them to disclose trading history or account statistics under false assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The instruction to generate a stats card in format="tweet" implies a specific social-media-oriented language/locale output mode without offering the user a language choice. This can violate language/locale policy when the user has not opted into English or that platform-specific communication style.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The sharing instructions prescribe tweet output and provide example posts and hashtags aimed at X/Twitter, but do not offer any language or locale selection. This is a natural-language policy concern because the skill steers user-facing content into a presumed default language/context without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.