Back to skill

Security audit

polymarket-wallet-xray

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly analyzes public wallet activity, but it also asks for an unrelated Simmer API key and includes authenticated account-status behavior despite claiming no authentication is needed.

Review this skill before installing. Use the wallet analyzer only in an isolated environment, avoid exporting a live SIMMER_API_KEY unless you intentionally want the Simmer account-status helper, and do not rely on its copytrading allocation recommendations as financial advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:3
Finding

Unnecessary and Unpinned Third-Party Dependencies Expand the Supply-Chain Attack Surface

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
clawhub.json:3
Finding

Global API Credential Requirement Exceeds the Primary Analyzer’s Minimum Privileges

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents the skill as a non-production framework while also describing behavior consistent with an automated trading system elsewhere in the same disclaimer. Even if this inconsistency is only documentation-level, it materially weakens user trust and informed consent by obscuring whether the skill merely analyzes public wallets or can execute trades with real funds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The disclaimer explicitly states that running the skill with --live will place real on-chain orders, which directly conflicts with the declared skill purpose of read-only Polymarket wallet analysis. This kind of scope mismatch is dangerous because users may install a supposedly passive analytics skill that actually contains or anticipates trade-execution behavior, increasing the risk of deceptive capability, accidental fund movement, or hidden wallet-interacting code elsewhere in the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose materially differs from the observed behavior: it claims unauthenticated public-wallet analysis, but the implementation reportedly relies on an authenticated Simmer API and account-status functionality. This kind of behavior mismatch is dangerous because users may provide credentials or run the skill under false assumptions, enabling unintended data access and trust abuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file’s actual behavior targets authenticated Simmer account data even though the skill is ներկայացված as a Polymarket wallet analysis tool using public APIs with no authentication. This mismatch is dangerous because it can trick users or an agent runtime into supplying sensitive credentials and running a different capability than expected, which is a strong indicator of deceptive or substituted functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script reads an authenticated API key from the environment despite the skill metadata claiming no authentication is needed and only public APIs are used. In this context, that discrepancy is especially dangerous because users or orchestration systems may expose secrets they would not have provided if the skill were honestly described, enabling unauthorized access to private account data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill produces direct, prescriptive financial advice such as 'Safe to copytrade' with specific capital allocation percentages, without suitability checks, uncertainty disclosures, or requiring user confirmation. In this skill context, that is more dangerous because the tool presents itself as an analytical wallet forensics system, which can create unwarranted trust in heuristic outputs and drive users toward risky real-money decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises network and environment-dependent behavior but does not declare any explicit tool scope or permissions boundary. That creates a transparency and governance gap: an agent or user may authorize or run it without realizing it can access environment variables and make outbound requests, which increases the chance of overbroad execution or secret exposure in downstream implementations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest states the skill queries Polymarket public APIs directly, while later content says analysis is performed via Simmer API. In a security context, inaccurate declarations about data sources and trust boundaries are dangerous because they conceal third-party dependency and authentication requirements, undermining informed consent and review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation says no authentication is needed and that only public APIs are used, yet setup instructions require a Simmer API key and later text says data comes via Simmer API. This contradiction can mislead users into disclosing credentials unnecessarily or trusting the skill with a broader access model than expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstrings and CLI text explicitly describe a Simmer account-status utility, contradicting the declared Polymarket wallet-xray purpose. In skill ecosystems, this kind of contradiction increases the risk of operator confusion, accidental execution of the wrong tool, and concealment of unauthorized data access behavior behind unrelated metadata.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module usage docs show python wallet_xray.py 0x1234...abcd "Bitcoin", implying the second positional argument is a market/topic filter. In the actual implementation, the second positional argument is defined as market but only used as wallet2 when --compare is set, and is otherwise ignored entirely, which contradicts the documented usage and intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline comment states Fetch trades from Polymarket CLOB API, but get_wallet_trades builds requests to https://data-api.polymarket.com/activity. This is a direct documentation-to-code contradiction about what backend is being queried.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.