Back to skill

Security audit

Polymarket Ai Divergence

Security checks for vulnerabilities and agentic risk

Overview

This real-money trading skill is mostly coherent, but it understates several financial and credential risks that users should review before installing.

Review this skill carefully before installing. Use a dedicated low-balance wallet, treat WALLET_PRIVATE_KEY as highly sensitive, verify all configured endpoints, and assume --live can place real trades. The current artifact should not be relied on to trade only zero-fee markets, and it may redeem positions automatically when run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/status.py:18
Finding

Bearer API Key Can Be Sent to an Arbitrary Configurable Destination

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ai_divergence.py:421
Finding

Documented Zero-Fee Trading Safeguard Is Not Enforced

Content
View full analysis
0 else "no" edge = abs(div) # Subtract fee from edge — only trade if edge exceeds fee net_edge = edge - fee_pct if net_edge < MIN_EDGE: log(f" ⏭️ {question}... — edge {edge:.1%} - fee {fee_pct:.1%} = net {net_edge:.1%} < min {MIN_EDGE:.1%}") skip_reasons.append(f"net edge too low after {fee_rate_bps}bps fee") continue edge = net_edge # Use fee-adjusted edge for Kelly sizing ``` ### Technical Analysis The Skill documentation repeatedly states that live execution is restricted to zero-fee markets. The implementation does not enforce that invariant. Instead, it subtracts the fee from the estimated edge and permits a trade whenever the remaining edge meets `MIN_EDGE`. Consequently, a market with a nonzero fee remains eligible for live trading. In addition, this expression treats missing fee information as zero: ```python fee_rate_bps = ctx_market.get("fee_rate_bps", 0) ``` Although a completely failed context request is rejected earlier, a successful but incomplete response lacking `fee_rate_bps` is accepted as a zero-fee market. This is a fail-open decision for a financially significant safeguard. ...[truncated 1404 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tainted flow: 'req' from os.environ.get (line 30, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/status.py (reported line 34)May include surrounding context.

python
f"{SIMMER_API_URL}/api/sdk/markets",
            headers={"Authorization": f"Bearer {api_key}"}
        )
        data = json.loads(urlopen(req, timeout=30).read())
        markets = data.get("markets", [])
        
        high_div = [m for m in markets if abs(m.get("divergence") or 0) > 0.10]

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose centers on an automated mispricing-trading strategy: scanning for AI-vs-market divergence, checking fees and safeguards, sizing positions with Kelly, and executing trades. The supplied code does none of that. It is a lightweight synchronous client for Polymarket's Gamma API, providing only market/event search and retrieval helpers plus response parsing. Its functionality is limited to fetching and normalizing metadata such as prices, liquidity, volume, tags, and event details. While such data access could support a future trading strategy, the code chunk itself is strictly research/data-access infrastructure and does not implement the strategy described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code is related to the general theme of AI divergence scanning, since it fetches market data and summarizes divergence levels. However, the declared purpose centers on identifying tradable mispricings and then executing trades with Kelly sizing after checking fees and safeguards. This script only provides a read-only status summary of divergences and a top opportunity. Because key advertised behaviors—trade execution, sizing, and fee/safeguard checks—are absent, the supplied code chunk does not accurately represent the full declared functionality and is materially narrower in purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents use of environment variables for secrets and multiple network/API interactions, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing capability declarations reduce transparency and make it easier for a skill to access secrets or external services without clear user consent or policy enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the user to provide a wallet private key and store it in an environment variable, but it does not include explicit guidance on secure handling, least exposure, or the consequences of compromise. In a trading context, theft or leakage of this key can enable irreversible loss of funds and unauthorized transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick commands advertise a live trading mode without clearly warning that it can place real-money trades that may be immediate and irreversible. In the context of a market-trading skill, omission of a risk warning materially increases the chance of accidental financial loss by users who may treat the command as a harmless test.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill 'executes trades on zero-fee markets with sufficient edge.' In code, fee_rate_bps is subtracted from the edge and trading proceeds whenever the net edge remains above MIN_EDGE, which allows non-zero-fee markets to be traded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest advertises support for a WALLET_PRIVATE_KEY for self-custody trading but only describes when it is needed, not that it is a highly sensitive secret whose exposure can directly lead to loss of funds. In a trading skill that places real bets, normalizing private-key entry without explicit risk and handling guidance increases the chance users provide dangerous credentials without understanding the consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Automatic redemption is a separate account-management action not mentioned in the manifest description, which focuses on scanning divergence, checking fees/safeguards, and executing trades. This expands the operational behavior beyond the stated scan-and-trade flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.