T09 · Insecure Skill Coding Practices
- Location
fast_scaler.py:207- Finding
Concurrent executions can bypass the daily trading budget
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This real-money trading skill mostly matches its stated purpose, but it needs review because some account actions and live-run safety controls are under-scoped.
Install only after reviewing the live-trading risks. Use a dedicated low-balance Simmer account or wallet, start in paper mode, pin the SDK version before production use, avoid exposing WALLET_PRIVATE_KEY unless strictly required, and do not run the provided cron live workflow without a lock or other single-instance control.
fast_scaler.py:207Concurrent executions can bypass the daily trading budget
clawhub.json:7Trading SDK dependency is not pinned to an audited release
The declared behavior describes an automated Polymarket BTC trading strategy, but the detected implementation behavior reportedly lacks the core gating, sizing, and trade-execution logic and instead centers on spread-computation testing. This mismatch is dangerous because users may grant trading-related trust, permissions, or operational assumptions to a skill that does not actually do what it claims, undermining safe review and potentially masking other unintended behavior.
The skill advertises commands that require environment access, file interaction, and outbound network usage, but it declares no explicit tool scope or permissions boundary. In an agent framework, that omission can lead to overbroad execution rights, making it easier for the skill to access secrets, modify local state, or reach external services without clear operator approval.
The document tells users to use the skill when they want a 'validated magnitude filter' while elsewhere clearly stating that the backtest was retracted and there is no validated edge. This contradictory safety/efficacy messaging can mislead users into risking real funds based on a nonexistent validation, which is especially harmful in a live-trading context.
Claiming a 'validated magnitude filter' despite repeated statements that the strategy has no validated edge is a misleading quality and performance assertion. In a financial trading skill, such overstatement can drive unsafe reliance, increase the chance of real-money loss, and impair informed consent by operators.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# crontab -e
* * * * * cd /path/to/skill && python fast_scaler.py --live --quiet
The manifest frames the 0.10% magnitude threshold as the condition the strategy is built around and says it only fires when that threshold is met. In code, magnitude_gate_pct is user-configurable and the only enforcement is a help string warning not to lower it, so the skill can be made to trade below the claimed threshold.
The manifest describes a skill for trading Polymarket BTC 5-minute fast markets only. However, the configuration and symbol map allow changing the asset to ETH or SOL and the window to 15m or 1h, which expands operational scope beyond the declared BTC 5-minute strategy.
The validation document reveals the skill performs auto-redeem behavior that is outside the manifest's stated trading-only scope. Undeclared fund-moving or position-settlement behavior weakens operator oversight and can cause users to grant or run capabilities they did not knowingly approve, which is especially sensitive in an automated trading skill.
The document describes GTC order cleanup logic that is not disclosed in the manifest, meaning the skill may cancel standing orders as a side effect beyond its declared scope. In a trading context, undisclosed order-cancellation behavior can materially affect exposure, execution strategy, and account state, creating operational and financial risk if users are unaware of it.
The manifest describes a fast-market entry strategy based on BTC momentum and conviction-scaled sizing. The code also periodically auto-redeems winning positions from resolved markets, which is an account-management capability outside the stated strategy description.
The code reads the sensitive environment variable SIMMER_API_KEY and uses it to initialize a live trading client, but this specific credential access is not accompanied by a nearby user-facing warning, confirmation, or explicit disclosure in the code path itself. For code files, accesses to sensitive environment variables should have some visible disclosure unless clearly covered elsewhere; in this file the nearby output only reports missing-key errors, not that credentials will be consumed for live trading when present.
No suspicious patterns detected.