Back to skill

Security audit

polymarket-signal-sniper

Security checks for vulnerabilities and agentic risk

Overview

The main signal scanner is disclosed and read-only, but the package also includes an undocumented account-status script that can read sensitive Simmer portfolio and position data.

Review this package before installing. Use a least-privilege Simmer API key if available, and avoid or remove scripts/status.py unless you intentionally want local account balance and position reporting. I found no evidence that the skill auto-trades, installs persistence, or sends data anywhere other than configured RSS sources and Simmer APIs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A description-behavior mismatch is dangerous because users and orchestrators may grant trust and permissions based on the declared purpose, while the underlying implementation appears to access authenticated account or portfolio data and perform materially different actions. That creates a confused-deputy risk: a supposedly passive news-monitoring skill could expose sensitive financial data or influence trading workflows under false pretenses.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
4. **Only trade if** the article bears on the resolution criteria, it is not priced in, and no warning argues against it. If it trades, pass `source="sdk:signalsniper"` so the trade is attributed to this skill:

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This script operates on Simmer trading accounts by querying authenticated portfolio and positions endpoints, which is materially outside the declared skill purpose of monitoring Polymarket-related news signals and never trading. That mismatch is dangerous because it expands the skill's privilege and data-access scope to sensitive financial account information, creating hidden account-surveillance capability that a user would not reasonably expect from the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads SIMMER_API_KEY from the environment and uses it to access authenticated portfolio and positions data, including balances, exposures, PnL, concentration, and open positions. In a skill whose stated role is signal monitoring rather than account access, this is dangerous because it unnecessarily handles sensitive credentials and financial data, increasing the risk of unauthorized data collection, privacy violations, and misuse if the skill is installed or run under broader agent permissions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documentation advertises network, environment, and file-backed behavior but does not declare any explicit tool scope or allowed-tools boundary. In an agent ecosystem, missing scope declarations can cause over-broad execution privileges, making it easier for the skill to read secrets, write persistent state, or access the network beyond what a user expects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.