T09 · Insecure Skill Coding Practices
- Location
scripts/status.py:18- Finding
Bearer API Key Can Be Sent to an Arbitrary Configurable Destination
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This real-money trading skill is mostly coherent, but it understates several financial and credential risks that users should review before installing.
Review this skill carefully before installing. Use a dedicated low-balance wallet, treat WALLET_PRIVATE_KEY as highly sensitive, verify all configured endpoints, and assume --live can place real trades. The current artifact should not be relied on to trade only zero-fee markets, and it may redeem positions automatically when run.
scripts/status.py:18Bearer API Key Can Be Sent to an Arbitrary Configurable Destination
ai_divergence.py:421Documented Zero-Fee Trading Safeguard Is Not Enforced
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
f"{SIMMER_API_URL}/api/sdk/markets",
headers={"Authorization": f"Bearer {api_key}"}
)
data = json.loads(urlopen(req, timeout=30).read())
markets = data.get("markets", [])
high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]
This is a clear description-behavior mismatch. The declared purpose centers on an automated mispricing-trading strategy: scanning for AI-vs-market divergence, checking fees and safeguards, sizing positions with Kelly, and executing trades. The supplied code does none of that. It is a lightweight synchronous client for Polymarket's Gamma API, providing only market/event search and retrieval helpers plus response parsing. Its functionality is limited to fetching and normalizing metadata such as prices, liquidity, volume, tags, and event details. While such data access could support a future trading strategy, the code chunk itself is strictly research/data-access infrastructure and does not implement the strategy described.
The code is related to the general theme of AI divergence scanning, since it fetches market data and summarizes divergence levels. However, the declared purpose centers on identifying tradable mispricings and then executing trades with Kelly sizing after checking fees and safeguards. This script only provides a read-only status summary of divergences and a top opportunity. Because key advertised behaviors—trade execution, sizing, and fee/safeguard checks—are absent, the supplied code chunk does not accurately represent the full declared functionality and is materially narrower in purpose.
The skill documents use of environment variables for secrets and multiple network/API interactions, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing capability declarations reduce transparency and make it easier for a skill to access secrets or external services without clear user consent or policy enforcement.
The skill instructs the user to provide a wallet private key and store it in an environment variable, but it does not include explicit guidance on secure handling, least exposure, or the consequences of compromise. In a trading context, theft or leakage of this key can enable irreversible loss of funds and unauthorized transactions.
The quick commands advertise a live trading mode without clearly warning that it can place real-money trades that may be immediate and irreversible. In the context of a market-trading skill, omission of a risk warning materially increases the chance of accidental financial loss by users who may treat the command as a harmless test.
The manifest description says the skill 'executes trades on zero-fee markets with sufficient edge.' In code, fee_rate_bps is subtracted from the edge and trading proceeds whenever the net edge remains above MIN_EDGE, which allows non-zero-fee markets to be traded.
The manifest advertises support for a WALLET_PRIVATE_KEY for self-custody trading but only describes when it is needed, not that it is a highly sensitive secret whose exposure can directly lead to loss of funds. In a trading skill that places real bets, normalizing private-key entry without explicit risk and handling guidance increases the chance users provide dangerous credentials without understanding the consequences.
Automatic redemption is a separate account-management action not mentioned in the manifest description, which focuses on scanning divergence, checking fees/safeguards, and executing trades. This expands the operational behavior beyond the stated scan-and-trade flow.
No suspicious patterns detected.