Back to skill

Security audit

polymarket-weather-trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent with its trading purpose, but it needs review because it can place real-money trades and one advertised safeguard path can fail open.

Review this before installing because it can trade real money. Start in dry-run or TRADING_VENUE=sim, set tight platform caps, avoid providing WALLET_PRIVATE_KEY unless needed, and do not use --live or --no-safeguards until you accept that some safeguards can be bypassed if context data is unavailable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a trading skill for Polymarket weather markets using NOAA and Open-Meteo forecasts through Simmer API. The supplied code does not trade, place bets, access Polymarket, invoke Simmer API, or implement market strategy logic. Instead, it is an offline archive-building script that fetches historical forecast data from Open-Meteo's Previous Runs endpoint, performs date/chunk/DST validation, computes daily highs/lows for multiple forecast leads, and outputs a JSON file. While weather forecasting data is relevant to the broader domain, the code chunk's primary purpose is materially different from the declared trading functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill trades Polymarket weather markets using NOAA/Open-Meteo forecasts through Simmer API. However, this code chunk is not implementing trading or forecasting behavior. Its sole purpose is to act as an agent-facing test gate: it prints instructions and keep/kill/fix criteria, then invokes pytest on a replay discovery test file and exits based on test success. That is a materially different primary purpose from weather-market trading. While this script may belong to the broader skill repository as support tooling, the code shown does not accurately match the declared end-user functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on weather-market trading driven by external forecast sources (NOAA and Open-Meteo) and suggests strategy execution or forecast checking for weather bets. The actual code does none of that. It only initializes a read-only Simmer client, fetches portfolio and positions data, and prints account summaries and open positions. There is no weather data access, no forecast logic, no market-selection logic, and no trade placement. This is a materially different primary purpose: account monitoring rather than weather-market trading.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares capabilities that include environment-variable use, file writes, network access, and shell execution, but it does not declare any explicit tool scope such as permissions or allowed-tools. In a skill that can touch API keys, wallet private keys, and trading commands, this absence weakens least-privilege controls and increases the chance of unintended or overly broad execution by an agent runtime.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_backtest_gate.py (reported line 104)May include surrounding context.

python
print(KEEP_KILL, flush=True)
    print(flush=True)
    print(f"── pytest {TEST_FILE.relative_to(SKILL_DIR.parent.parent)} ──", flush=True)
    result = subprocess.run(
        [sys.executable, "-m", "pytest", str(TEST_FILE), "-q"],
        cwd=str(SKILL_DIR.parent.parent),
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather_trader.py (reported line 533)May include surrounding context.

python
}


OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"

def _fetch_openmeteo_at(lat: float, lon: float, tz: str, label: str) -> dict:
    """Internal: fetch Open-Meteo daily highs/lows at the given coords."""

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level docstring says the skill 'Trades Polymarket weather markets using NOAA forecasts,' which implies a NOAA-centric scope. In code, the skill also supports many international cities and stations via Open-Meteo and performs discovery/import of Polymarket markets through Simmer, which is broader behavior than the module documentation states.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring states 'Execute a buy trade via Simmer SDK with source tagging,' but the implementation accepts a side argument and passes it through to client.trade(...). That documentation actively narrows the function's intent in a way that does not match what the code actually allows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.