Back to skill

Security audit

Polymarket CLI

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Polymarket CLI helper, but it combines financial account control with unsafe installation guidance and weak confirmation safeguards.

Review this skill carefully before installing. Prefer Homebrew or a pinned, verifiable release instead of the curl-to-shell installer. Do not pass private keys on the command line unless you understand the exposure risks. For any order, approval, bridge deposit, wallet reset, cancellation, or API key change, require the agent to show the exact command and wait for your explicit confirmation before it runs.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:29
Finding

Unverified Remote Installer Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:29
  • references/troubleshooting.md:5

Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

SKILL.md:29

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

references/troubleshooting.md:5

text
- 确认安装:`brew install polymarket` 或 `curl -sSL ... | sh`

Technical Analysis

The primary installation procedure downloads a shell script from the mutable main branch of an external GitHub repository and immediately passes its contents to sh. The downloaded content is not pinned to a release or commit and is not authenticated through a cryptographic signature or verified against a trusted checksum. It is also not saved for inspection before execution.

Consequently, the effective code executed by this Skill can change after the Skill itself has been reviewed. Compromise of the upstream repository, maintainer account, branch, or release workflow could turn the installer into an arbitrary-code delivery mechanism. The abbreviated troubleshooting instruction reinforces the same unsafe installation pattern, although its ellipsis means that particular example is not independently executable without substitution.

This behavior exceeds the minimum privileges required to install or use the declared CLI. Installation requires placing a known executable in an appropriate location; it does not require granting an unreviewed, mutable network response unrestricted shell execution. The remote script runs with all permissions available to the invoking Agent or user.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or another mechanism capable of modifying install.sh on the main branch.
  2. The attacker changes the installer to include malicious shell commands.
  3. An Agent follows SKILL.md after determining that the `p ...[truncated 1528 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove every curl | sh installation recommendation, including the abbreviated troubleshooting example.
  2. Pin installation artifacts to a specific reviewed release version or immutable commit rather than the mutable main branch.
  3. Download the artifact without executing it immediately:
    bash
    curl --fail --show-error --location --output polymarket-installer.sh \
      https://example.invalid/path/to/pinned/version/install.sh
    
  4. Verify the downloaded artifact against a checksum obtained through a trusted, independently authenticated release channel:
    bash
    echo '<EXPECTED_SHA256>  polymarket-installer.sh' | sha256sum --check -
    
  5. Prefer cryptographic signature verification when the upstream project publishes signed release artifacts.
  6. Allow inspection of the downloaded script before execution and obtain explicit user approval.
  7. Run installation with the least-privileged account possible. Do not use sudo unless a reviewed installation step demonstrably requires it.
  8. Prefer a pinned package-manager release where package provenance and integrity verification are available.
  9. Update references/troubleshooting.md:5 to refer only to the hardened, pinned installation procedure rather than encouraging direct remote-shell execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh construct is a classic command-chaining pattern that turns retrieved content into immediate shell execution. This removes opportunities for review and makes any compromise of the source, transport, or substituted URL equivalent to arbitrary command execution on the system.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

若未安装,优先一键脚本:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

或 Homebrew:

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The troubleshooting guide recommends installing via a pipe-to-shell pattern (curl -sSL ... | sh), which executes remote content immediately without prior verification. In a CLI that manages wallets, private keys, approvals, bridge activity, and trading operations, this is especially dangerous because a compromised installer could steal secrets, alter transaction behavior, or backdoor the user's environment.

Content

Scanner excerpt · references/troubleshooting.md (reported line 5)May include surrounding context.

md
## 1) `command not found: polymarket`

- 确认安装:`brew install polymarket` 或 `curl -sSL ... | sh`
- 确认 PATH:`which polymarket`

## 2) 钱包相关失败 / 无法签名

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The operational instructions are written as directives in Chinese and implicitly require the interaction flow to follow that locale, while the file does not offer an opt-in or alternative language. This can violate language/locale policy when a skill imposes a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation path recommends piping a remotely fetched script directly into the shell with no integrity verification, pinning, or warning. If the upstream repository, network path, or referenced branch is compromised, arbitrary code will execute immediately on the host running the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to perform sensitive write operations such as order placement, cancellations, approvals, bridge deposits, API key management, and wallet-affecting actions without requiring explicit user confirmation at execution time. In an agent context, this can translate a vague or spoofed request into real financial loss or irreversible account changes, especially when credentials may already be configured in the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly shows polymarket wallet import <private_key> and also advertises --private-key <KEY> on the command line without warning that shell history, process listings, terminal logs, and screenshots can expose secrets. In a trading/crypto context, disclosure of a private key can directly lead to wallet compromise and irreversible asset loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The reference includes destructive commands such as wallet reset, cancel-market, and cancel-all with little or no prominent warning about irreversibility or account-wide impact. In an automation-oriented CLI, users may copy/paste or script these commands and unintentionally wipe configuration or cancel active positions/orders, causing financial and operational harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

API key creation and deletion are documented without noting that generated credentials are sensitive secrets and that deletion can break existing bots, integrations, or trading workflows. In a financial automation context, poor key handling can enable unauthorized trading access or cause denial of service for legitimate operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire troubleshooting guide is written in Chinese, and there is no indication that the skill offers users a language/locale choice or that the content is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This line fetches an external script from GitHub and executes it, creating a direct software supply-chain risk. In a skill designed for terminal automation, this is more dangerous because an agent may run the command non-interactively, giving remote code execution to anyone who can alter the fetched content.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

若未安装,优先一键脚本:

bash
curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh

或 Homebrew:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The file presents the command reference entirely in Chinese, which can amount to forcing a specific language without user opt-in under the stated policy. There is no indication that the skill is region-specific or that alternative language support is intentionally limited and documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.