Back to skill

Security audit

Polymarket 5m Trading

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed automated Polymarket trading skill, but it handles live trading credentials and can send derived wallet trading credentials to an unvalidated custom backend URL.

Install only if you understand that live mode can place real Polymarket orders and can lose money. Keep it in dry-run unless you intentionally pass --live, use a dedicated low-balance wallet, avoid setting AIONMARKET_BASE_URL unless it is a trusted documented endpoint, and prefer pinned/reviewed dependency versions before using it with real funds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
run_skill.py:43
Finding

Unrestricted Backend Override Can Expose API and Wallet Credentials

Content
View full analysis
AionMarketClient: base_url = env("AIONMARKET_BASE_URL") if base_url: return AionMarketClient(api_key=get_api_key(), base_url=base_url) return AionMarketClient(api_key=get_api_key()) ``` The client created with the configurable endpoint is subsequently used to inspect and register wallet credentials: ```python def ensure_wallet_credentials(client: AionMarketClient, private_key: str) -> tuple[str, ApiCreds]: wallet, creds = derive_wallet_bundle(private_key) status = client.check_wallet_credentials(wallet) if isinstance(status, dict) and status.get("success") is False: raise RuntimeError(str(status.get("error") or status)) if not status.get("hasCredentials"): client.register_wallet_credentials( wallet_address=wallet, api_key=creds.api_key, api_secret=creds.api_secret, api_passphrase=creds.api_passphrase, ) return wallet, creds ``` The corresponding configuration explicitly exposes the endpoint override: ```json { "name": "AIONMARKET_BASE_URL", "required": false, "description": "Optional non-default AION backend URL when your environment documents one." } ``` ### Technical Analysis `AIONMARKET_BASE_URL` is accepted without validating its scheme or hostname. The resulting `AionMarketClient` is initialized with the user's AION API key and is also used by the live-trading credential-registration workflow. When live trading is enabled, the application derives Polymarket CLOB API credentials from `WALLET_PRIVATE_KEY`. If the configured backend reports that credentials are absent, the application sends the wallet address, API key, API secret, and API passphrase to that backend. The wall ...[truncated 1879 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Security-Sensitive Python Dependencies Are Not Version-Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_skill.py (reported line 517)May include surrounding context.

python
def main() -> int:
    load_dotenv(".env")
    args = parse_args()

    try:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill references sensitive environment-based capabilities, including API credentials and a live-trading private key, but does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, this weakens least-privilege controls and can allow the skill to access secrets or trading capability more broadly than a reviewer or runtime policy expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users how to enable live trading with real funds but does not present a clear warning that trades can cause irreversible financial loss. This is especially dangerous here because the strategy is automated, repetitive, and designed to place multiple live orders, increasing the chance of unintended losses from user misunderstanding or accidental activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

In --live mode, the skill places real BUY and SELL orders directly from command-line execution with no interactive confirmation, no secondary approval gate, and no explicit max-loss or spend cap beyond user-provided parameters. In a trading skill, this is materially risky because an accidental invocation, misconfiguration, or automation trigger can immediately execute real market activity using the wallet private key.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
0% confidence
Finding

No reportable SQP-3 issue was found. The reference to Polygon is a technical platform choice, not a language or locale policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest schedules the skill to run every 3 hours via cron, but provides no surrounding description of when the automation should or should not be active. For a manifest file, the activation condition is therefore broad and underspecified, which could lead to unintended periodic invocation if enabled in the wrong context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.