Back to skill

Security audit

Polymarket via Gina

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly for Gina-powered Polymarket trading, but it asks users to store a 90-day bearer token for real-money trading and automations with unclear scoping and confirmation boundaries.

Install only if you are comfortable giving this MCP connection access to Polymarket account data and real-money USDC trading functions. Keep the token out of shared files, logs, repos, and backups; start with read-only prompts; confirm how Gina scopes tokens and authorizes each trade, redemption, cancellation, and automation; and revoke the token immediately if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:63
Finding

Long-Lived Bearer Token Used for Financially Privileged MCP Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:63-93; duplicated in README.md:11-31
Vulnerability Type: Long-lived, insufficiently scoped bearer-token configuration
Risk Level: Medium

Vulnerable Code

SKILL.md:63-85:

markdown
## Quick Start

1. Sign in at [askgina.ai](https://askgina.ai) and open **Agent Setup** (sidebar or `https://askgina.ai/agent-setup`).
2. Give your token a name (e.g. "OpenClaw on MacBook") and click **Generate Token**.
3. Copy the connection config immediately — the token is only shown once.
4. Paste the config into your MCP client:

```json
{
  "mcpServers": {
    "gina-predictions": {
      "transport": "http",
      "url": "https://askgina.ai/ai/predictions/mcp",
      "headers": {
        "Authorization": "Bearer <PASTE_TOKEN_HERE>"
      }
    }
  }
}
  1. Restart your MCP client and ask: "What can you do with gina".
text

`SKILL.md:87-93`:

```markdown
## How It Works

- **Auth**: Long-lived JWT token generated at `https://askgina.ai/agent-setup`. Tokens expire after 90 days. You can have up to 5 active tokens and revoke any of them from the Agent Setup page.
- **Wallets**: Self-custodial via [Privy](https://privy.io). You own your keys.
- **Trades**: Execute on-chain on Polymarket (Polygon / USDC).
- **Gas**: Gina provides gas sponsorship to help cover transaction fees.
- **Safety**: Large trades require explicit confirmation before executing.

The same persistent bearer-token configuration and 90-day expiration period are documented in README.md:11-31.

Technical Analysis

The Skill instructs users to place a long-lived bearer JWT directly in persistent MCP client configuration. The token is then transmitted to the declared third-party endpoint, https://askgina.ai/ai/predictions/mcp, whenever the MCP service is accessed.

Network transmission is necessary for the Skill's declared remote-service functional ...[truncated 2591 chars]

Remediation
View remediation

Remediation Suggestions

  1. Introduce granular token scopes. Provide separate permissions for market discovery, portfolio reads, trading, order cancellation, redemption, and automation management.
  2. Default to read-only access. Newly generated tokens should be read-only unless the user explicitly enables each fund-affecting capability.
  3. Reduce token lifetime. Prefer short-lived access tokens backed by narrowly protected refresh credentials or an interactive reauthorization flow.
  4. Avoid literal secret storage in configuration. Document integrations with operating-system keychains, MCP secret providers, or environment-variable references rather than requiring the JWT value directly in a configuration file.
  5. Require transaction authorization. Require explicit, transaction-bound confirmation for every trade, cancellation, redemption, and automation that can move or commit funds—not only transactions categorized as large.
  6. Support enforceable financial limits. Add per-transaction, daily cumulative, market-specific, and automation spending limits enforced by the server.
  7. Constrain automation authority. Automation tokens should have independent scopes, expiration times, allowed markets, maximum order sizes, and maximum cumulative expenditure.
  8. Improve credential monitoring. Expose token last-use information, source metadata, security notifications, rapid revocation, and automatic revocation when suspicious access is detected.
  9. Harden the documentation. Explicitly warn users not to commit, synchronize, log, or share MCP configuration files containing bearer tokens, and document secure file-permission requirements.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly states that users can 'Just type natural language prompts — no special syntax needed,' which encourages invocation from unconstrained free-form requests. In an agent environment that routes tools based on user text, this can cause accidental activation during ordinary conversation and may trigger access to trading, account, or automation capabilities without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example prompts include broad phrases like 'What can you do Gina', 'run a query', and short trading commands that resemble normal assistant requests. Because this skill controls real-money trading and account actions, such generic prompts increase the chance of prompt collision, unintended tool selection, or user confusion that leads to unauthorized or mistaken financial actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.