Back to skill

Security audit

polymarket-elon-tweets

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed automated trading skill, but it needs review because it can place real-money trades and asks users to expose sensitive wallet/API credentials through an unpinned SDK setup.

Review this carefully before installing. Use managed-wallet mode if available, avoid putting a high-value wallet private key in the general environment, use a dedicated low-balance wallet if live trading, and pin/review the SDK version before giving it API or signing credentials. Dry-run mode is the safer default; only use --live after confirming limits, market scope, and exit behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:9
Finding

Security-Critical SDK Dependency Is Not Pinned to an Audited Version

Content
View full analysis
=0.11.1" ] ``` The installation instructions in `SKILL.md:42-44` similarly install the latest package version satisfying the package name: ```bash pip install simmer-sdk ``` ### Technical Analysis The Skill permits any current or future `simmer-sdk` release greater than or equal to version `0.11.1`. There is no upper version boundary, dependency lockfile, integrity hash, or other mechanism binding installation to the version that was reviewed. This dependency is security-critical. The Skill imports and invokes it directly, passes the Simmer API key into `SimmerClient`, and documents that the SDK handles wallet signing when `WALLET_PRIVATE_KEY` is present. A compromised upstream release, publisher account, package distribution channel, or transitive dependency could therefore execute arbitrary Python code with the same privileges as the Skill. No evidence shows that the current SDK package is malicious. The vulnerability is the absence of controls preventing a future, substituted, or compromised release from silently changing the effective code executed by the Skill. ### Attack Path 1. An attacker compromises the package publisher, package repository, or a transitive dependency used by `simmer-sdk`. 2. The attacker publishes a malicious version satisfying `>=0.11.1`. 3. A user installs or updates the Skill using `pip install simmer-sdk`, which resolves to the compromised version. 4. The malicious package executes when imported or when `SimmerClient` is initialized. 5. It reads `SIMMER_API_KEY` and potentially `WALLET_PRIVATE_KEY` from the process environment. 6. It can transmit those credentials, alter market data, submit unauthorized trades, or execute arbitrary operations permitted to the Skill process. ### Impact Assessment Successful exploitation gran ...[truncated 725 chars]
Remediation
View remediation
" ] ``` 2. Update `SKILL.md` to install the same exact version. 3. Generate and retain a lockfile containing all transitive dependency versions. 4. Require package hashes during installation, for example through a hashed requirements file and `pip install --require-hashes`. 5. Verify package provenance and publisher identity before approving upgrades. 6. Review SDK release notes and security-sensitive changes before modifying the pinned version. 7. Run the Skill in an isolated environment with access only to required files, network destinations, and credentials. 8. Avoid exposing a wallet private key to the process when managed-wallet functionality is sufficient. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Wallet Private Key Is Exposed Through the Process Environment

Content
View full analysis
` - Do NOT attempt to sign orders manually or modify the skill code — the SDK handles it ``` ### Technical Analysis A cryptocurrency wallet private key is a high-value signing credential. Storing it in a general process environment makes it available to all Python modules imported into the Skill, including the third-party Simmer SDK and optional `tradejournal` integrations. Environment variables may also be exposed through inherited child processes, debugging tools, process diagnostics, crash reports, container configuration, automation logs, or accidental command history, depending on how the user sets and launches the Skill. The project code does not explicitly transmit or print `WALLET_PRIVATE_KEY`, and no confirmed exfiltration endpoint was identified. The risk arises because the instructions expose the key to the full Skill process and every in-process dependency rather than limiting signing access to a narrowly scoped component. The instructions also conflict with `clawhub.json:19-22`, which states that the wallet key is optional and is not required for managed wallets. Describing it as required during setup may cause users to grant a sen ...[truncated 1572 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior claims automated market trading using XTracker and Polymarket-related logic, but the detected behavior is primarily account/portfolio access and status reporting. This mismatch is dangerous because users may grant sensitive credentials or approve execution under false assumptions about what the skill actually does, weakening informed consent and security review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup flow instructs the user to provide a wallet private key and store it in an environment variable, but it does not give a strong security warning or safer alternative. In the context of a trading skill, requesting a raw private key is highly sensitive because compromise enables direct wallet control and loss of funds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s behavior is materially inconsistent with the skill’s declared purpose: instead of analyzing Polymarket Elon tweet markets or XTracker data, it authenticates to a separate Simmer account service and retrieves portfolio and position data. In an agent-skill setting, this scope mismatch is dangerous because it can cause users or orchestrators to grant sensitive credentials and expose unrelated financial account information under a misleading manifest.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill describes capabilities that require environment access, file writes, and network calls, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this increases the chance the skill is invoked with broader privileges than users expect, especially since it handles API credentials and trading-related operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is broad enough that the skill may trigger for loosely related user requests such as checking stats, automating bets, or monitoring positions. Overly permissive trigger phrases can cause accidental activation of a skill that handles credentials, configuration, network access, and potentially live trading, increasing the risk of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest exposes that the skill can perform automated trading and optionally use a wallet private key, but it does not present an explicit warning about live financial transactions, loss risk, or key-handling sensitivity. In a trading automation context, omission of these warnings increases the chance that a user supplies sensitive credentials or enables execution without understanding that real-money trades may occur.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code uses a bearer token to access portfolio and positions endpoints for a Simmer account, which is unrelated to the stated Polymarket Elon tweet trading use case. This creates unnecessary access to sensitive financial data and increases the blast radius if the skill is misused, misconfigured, or socially engineered into obtaining credentials that users would not expect to share for this purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring says the script shows wallet balance, positions, and recent activity. In practice, the code only fetches portfolio summary and optionally open positions from two API endpoints, with no request or output related to recent activity/history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.