Back to skill

Security audit

Polymarket FastScaler

Security checks for vulnerabilities and agentic risk

Overview

This real-money trading skill mostly matches its stated purpose, but it needs review because some account actions and live-run safety controls are under-scoped.

Install only after reviewing the live-trading risks. Use a dedicated low-balance Simmer account or wallet, start in paper mode, pin the SDK version before production use, avoid exposing WALLET_PRIVATE_KEY unless strictly required, and do not run the provided cron live workflow without a lock or other single-instance control.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
fast_scaler.py:207
Finding

Concurrent executions can bypass the daily trading budget

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Trading SDK dependency is not pinned to an audited release

Content
View full analysis
=0.17.32" ] ``` The installation instructions similarly select the latest available compatible version: ```bash pip install simmer-sdk ``` ### Technical Analysis The Skill permits any future `simmer-sdk` release at or above version `0.17.32`. This dependency is security-sensitive because the code initializes it with `SIMMER_API_KEY` and delegates market discovery, account queries, redemption, cancellation, and real trade submission to it: ```python api_key = os.environ.get("SIMMER_API_KEY") _client = SimmerClient(api_key=api_key, venue=venue, live=live) ``` A future compromised, malicious, or behaviorally incompatible release can therefore execute with the privileges of the Skill process and receive the trading API credential. The lower bound does not provide reproducibility or ensure that the installed code is the version that was reviewed. No evidence indicates that the currently referenced package is malicious. The confirmed issue is that installation is not constrained to an audited artifact, leaving future installations exposed to upstream compromise or unsafe changes. ### Attack Path 1. An attacker compromises the package publisher account, package repository, or release process for `simmer-sdk`. 2. The attacker publishes a version greater than `0.17.32`. 3. A user installs or reinstalls the Skill using `pip install simmer-sdk` or the manifest requirement. 4. Package resolution selects the compromised release. 5. The Skill imports the package and passes `SIMMER_API_KEY` to `SimmerClient`. 6. The malicious dependency can read process environment variables, access files available to the process, make network requests, or alter wallet-facing operations. 7. It may exfiltrate the API key, ...[truncated 865 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared behavior describes an automated Polymarket BTC trading strategy, but the detected implementation behavior reportedly lacks the core gating, sizing, and trade-execution logic and instead centers on spread-computation testing. This mismatch is dangerous because users may grant trading-related trust, permissions, or operational assumptions to a skill that does not actually do what it claims, undermining safe review and potentially masking other unintended behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises commands that require environment access, file interaction, and outbound network usage, but it declares no explicit tool scope or permissions boundary. In an agent framework, that omission can lead to overbroad execution rights, making it easier for the skill to access secrets, modify local state, or reach external services without clear operator approval.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document tells users to use the skill when they want a 'validated magnitude filter' while elsewhere clearly stating that the backtest was retracted and there is no validated edge. This contradictory safety/efficacy messaging can mislead users into risking real funds based on a nonexistent validation, which is especially harmful in a live-trading context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Claiming a 'validated magnitude filter' despite repeated statements that the strategy has no validated edge is a misleading quality and performance assertion. In a financial trading skill, such overstatement can drive unsafe reliance, increase the chance of real-money loss, and impair informed consent by operators.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

  1. Set up cron (every minute)
    bash
    # crontab -e
    * * * * * cd /path/to/skill && python fast_scaler.py --live --quiet
    

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames the 0.10% magnitude threshold as the condition the strategy is built around and says it only fires when that threshold is met. In code, magnitude_gate_pct is user-configurable and the only enforcement is a help string warning not to lower it, so the skill can be made to trade below the claimed threshold.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for trading Polymarket BTC 5-minute fast markets only. However, the configuration and symbol map allow changing the asset to ETH or SOL and the window to 15m or 1h, which expands operational scope beyond the declared BTC 5-minute strategy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The validation document reveals the skill performs auto-redeem behavior that is outside the manifest's stated trading-only scope. Undeclared fund-moving or position-settlement behavior weakens operator oversight and can cause users to grant or run capabilities they did not knowingly approve, which is especially sensitive in an automated trading skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document describes GTC order cleanup logic that is not disclosed in the manifest, meaning the skill may cancel standing orders as a side effect beyond its declared scope. In a trading context, undisclosed order-cancellation behavior can materially affect exposure, execution strategy, and account state, creating operational and financial risk if users are unaware of it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes a fast-market entry strategy based on BTC momentum and conviction-scaled sizing. The code also periodically auto-redeems winning positions from resolved markets, which is an account-management capability outside the stated strategy description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code reads the sensitive environment variable SIMMER_API_KEY and uses it to initialize a live trading client, but this specific credential access is not accompanied by a nearby user-facing warning, confirmation, or explicit disclosure in the code path itself. For code files, accesses to sensitive environment variables should have some visible disclosure unless clearly covered elsewhere; in this file the nearby output only reports missing-key errors, not that credentials will be consumed for live trading when present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.