Back to skill

Security audit

polymarket-fast-loop

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed automated Polymarket trader, but it needs Review because live mode can cancel fast-market orders that may not belong to it and installs an unpinned trading SDK.

Install only after reviewing the live-order behavior. Before providing a wallet key or using --live, fix or disable the stale GTC cleanup so it cancels only orders definitively tagged by this skill, pin the exact reviewed simmer-sdk version, and run first in dry-run or an isolated account with small limits. Avoid unattended cron live trading until those issues are addressed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
fastloop_trader.py:968
Finding

Overbroad Cancellation of Unrelated Live Orders

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Security-Critical Trading SDK Is Not Reproducibly Pinned

Content
View full analysis
=0.17.32" ] ``` `SKILL.md`: ```bash pip install simmer-sdk ``` ### Technical Analysis The Skill delegates security-critical operations to `simmer-sdk`, including authenticated Simmer API access, configuration loading, wallet-related trading workflows, preflight checks, market imports, and live order submission. The metadata accepts every future version at or above `0.17.32`, while the documented installation command has no version constraint at all. The project provides no lockfile, package hash, or other integrity control. As a result, installation is not reproducible and may retrieve dependency code that was never reviewed with this Skill. This is particularly sensitive because the dependency runs in a process containing `SIMMER_API_KEY` and may also have access to `WALLET_PRIVATE_KEY` for self-custody trading. No malicious behavior in the currently referenced SDK was established by this audit; the risk arises from allowing future or substituted package versions to enter a credential-bearing and financially privileged execution path without review. ### Attack Path 1. A user follows the documented `pip install simmer-sdk` command, or an installer resolves the `simmer-sdk>=0.17.32` requirement. 2. The package manager selects the newest satisfying package from its configured index. 3. A compromised, malicious, or behaviorally incompatible future release is downloaded and installed. 4. Its installation or runtime code executes in the Skill's environment. 5. The dependency can potentially read environment variables available to the process and influence authenticated market discovery, wallet signing, or live order submission. ### Impact Assessment A compromised resolved ...[truncated 511 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill requires sensitive capabilities—environment access for API and wallet private keys, network access to external services, and implied file/config modification—yet it declares no explicit tool scope or permissions boundaries. In an agent environment, this creates an overprivileged integration risk: the agent may grant broader access than necessary, enabling secret exposure, unintended file changes, or unauthorized live trading if the skill is invoked without strict sandboxing.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a BTC-focused skill for 5-minute and 15-minute fast markets using Binance BTC/USDT momentum. In code, the configurable asset includes ETH and SOL, and the supported window mapping includes a 1h duration, extending the strategy beyond the stated scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · fastloop_trader.py (reported line 756)May include surrounding context.

python
if _is_replay():
        return None
    url = (
        f"https://api.binance.com/api/v3/klines"
        f"?symbol={symbol}&interval=1m&startTime={start_ms}&limit=1"
    )
    result = _api_request(url)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill can execute live trades once invoked with --live, but at the actual placement point it does not present an explicit high-salience confirmation or warning that real funds are about to be used. In an agent or automation context, this increases the risk of unintended irreversible financial actions from misconfiguration, prompt confusion, or unsafe orchestration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest presents the skill as a fast-market trader using momentum signals. The code can additionally call an import workflow for markets discovered via Gamma that are not already available in Simmer, which is a resource-management operation beyond straightforward trade execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.