Back to skill

Security audit

Aionmarket Trading

Security checks for vulnerabilities and agentic risk

Overview

This trading skill is clearly about real-money prediction-market automation, but it gives the agent too much default authority over wallet keys, approvals, trades, and fee transfers without enough user confirmation.

Review this before installing as a real-money trading automation skill. Use only a limited wallet, set strict risk and allowance caps, avoid broad or persistent approvals, require explicit confirmation for every approval, trade, and fee transfer, and prefer pinned dependencies plus a separate signer or hardware wallet where possible.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Error
Location
skill.md:139
Finding

Unpinned Third-Party Packages Expose Wallet Secrets to Supply-Chain Risk

Content
View full analysis
= 0.1.2`, a minimum version constraint does not ensure that the installed implementation is the version that was reviewed. These dependencies execute in the same Python process that receives: - `WALLET_PRIVATE_KEY` - `SOLANA_PRIVATE_KEY` - `AIONMARKET_API_KEY` - Derived Polymarket API credentials - Locally signed trading transactions Consequently, an unexpectedly updated or compromised package can access wallet secrets, alter destination addresses, modify signed-order parameters before signing, or submit unauthorized transactions. The audit found no evidence that the named packages are currently malicious; the vulnerability is the absence of reproducible and integrity-verified dependency controls. ### Attack Path 1. An attacker compromises a future release or distribution account for one of the dependencies, or causes an unsafe replacement package to be resolved. 2. A user follows the documented unpinned `pip install` command. 3. The mutable package version is installed and imported by the trading workflow. 4. The package executes while wallet private keys and API credentials are present in process memory or environment variables. 5. Malicious package code extracts credentials, changes transaction paramet ...[truncated 552 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:75
Finding

Automatic Trading and Token Approvals Bypass Transaction-Specific User Authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:254
Finding

Reusable Polymarket Credentials Are Transmitted to an Intermediary Service

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:489
Finding

Automatic Fee Delegation and Transfers Rely on Hardcoded Platform Wallets

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The skill requires the agent to access high-value secrets from a local .env file, including private keys for live trading wallets. While environment variables are common, instructing a broadly capable agent skill to consume raw private keys directly increases blast radius if the agent is compromised, logs values, or other skills gain access to the environment.

Content

Scanner excerpt · skill.md (reported line 152)May include surrounding context.

Create a .env file in your project root (add .env to .gitignore):

bash
# .env
AIONMARKET_API_KEY=sk_live_...
WALLET_PRIVATE_KEY=0xabc123...your_64_hex_char_private_key

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The sample code explicitly loads secrets from .env and reads WALLET_PRIVATE_KEY into process memory for signing and credential derivation. In the context of an agent skill that performs autonomous trading and approvals, direct secret handling is more dangerous because compromise or misuse of the runtime exposes complete wallet control.

Content

Scanner excerpt · skill.md (reported line 176)May include surrounding context.

md
from dotenv import load_dotenv
from py_clob_client.client import ClobClient

load_dotenv()  # loads .env file

private_key = os.environ["WALLET_PRIVATE_KEY"]

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation says strategy skills such as market discovery, signal generation, and automated loops are separate and that this skill does not cover autonomous market scanning loops. However, the heartbeat workflow explicitly tells the agent to call get_briefing() periodically and iterate over opportunityMarkets, which is a strategy-adjacent market-scanning capability not justified by a core trading-only skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The scope section explicitly excludes 'autonomous market scanning loops.' Later, the 'Workflow: Heartbeat / Briefing' section instructs periodic execution every 30s–15min and iterates through briefing.get("opportunityMarkets", []), which is an active contradiction rather than a mere omission.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The instruction not to ask the user to confirm balance, gas, allowance checks, or approval after the private key is available normalizes autonomous execution with live credentials. In a trading skill, this is especially dangerous because approvals and downstream actions can immediately affect wallet security and funds.

Content

Scanner excerpt · skill.md (reported line 81)May include surrounding context.

md
3. **Respect risk limits** — honour `riskLimit`, `maxTradesPerDay`, `maxTradeAmount`
4. **Fail loudly** — catch `ApiError` and surface the message; never swallow errors
5. **Self-custody** — wallet keys belong to the user; SDK only stores encrypted CLOB credentials
6. **Automate mechanical steps** — do not ask the user to manually confirm balance checks, gas checks, allowance checks, or approval after the private key is available
7. **Verify execution independently** — if the wrapper response is weak, validate through the corresponding venue (Polymarket or Kalshi) before reporting failure

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent not to ask the user to confirm approvals and to auto-approve spenders, then proceed to trade once keys are available. Approvals and orders can move real funds or expand third-party spending authority, so suppressing explicit user warning/consent materially increases the risk of unauthorized transactions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The default workflow tells the agent to auto-select a market candidate, auto-approve if needed, and then trade. Combining autonomous market selection with automatic approvals and execution materially increases the risk of unintended or manipulated trades without meaningful user review.

Content

Scanner excerpt · skill.md (reported line 93)May include surrounding context.

md
- default trade mode: `market`
- default buy size: `2` USDC
- default behavior: auto-select a valid market candidate from the requested strategy scope
- default pre-trade workflow: derive wallet, register wallet credentials, check balance, check gas, check allowance, auto-approve if needed, then trade
- default post-trade workflow: query recent venue-specific trades/orders (Polymarket orders or Kalshi positions/orders) if the SDK result is generic, null, or ambiguous

The agent should ask the user only for information it cannot safely infer or execute itself.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Telling the agent to auto-approve required spenders when allowance is missing and gas is sufficient authorizes changes to token spending permissions without a fresh user decision. Excessive or misdirected approvals can expose funds beyond the immediate intended trade.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

md
- Cancel stale open orders promptly
- Rotate API keys every 90 days
- Prefer market orders for simple one-shot execution unless the user explicitly requests a limit order
- Auto-approve required spenders when allowance is missing and gas is sufficient

### AVOID

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 127)May include surrounding context.

md
### AVOID

- Trading without checking `warnings` from market context
- Exceeding the agent's configured `maxTradeAmount`
- Sharing or logging API keys, CLOB secrets, or private keys
- Calling `cancel_all_orders()` without confirming with the user first

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 132)May include surrounding context.

md
### AVOID

- Trading without checking `warnings` from market context
- Exceeding the agent's configured `maxTradeAmount`
- Sharing or logging API keys, CLOB secrets, or private keys
- Calling `cancel_all_orders()` without confirming with the user first

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill extends beyond core trade execution into mandatory post-trade fee extraction and commission handling, including directing the agent to initiate additional fund transfers after trades. This creates a second money-moving workflow that benefits the platform/agent and increases the chance of undisclosed or unexpected asset movement beyond the user's intended trade.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fee collection section directs the agent to automatically trigger additional token transfers after a successful trade, but does not foreground that this is a separate funds movement distinct from the trade itself. Users may authorize trading without understanding that post-trade fee charging, delegate configuration, or approvals will also be executed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

This line combines pre-trade allowance verification with auto-approval in the specific context of enabling a platform delegate/fee collection path. Because it can expand a third party's ability to pull assets, it is more dangerous than ordinary operational automation.

Content

Scanner excerpt · skill.md (reported line 536)May include surrounding context.

md
1. User's Safe wallet must have **AllowanceModule** enabled
2. Platform Fireblocks address must be added as **delegate** in the AllowanceModule
3. Sufficient **pUSD token allowance** must be configured on the module
4. The agent should verify allowance before trading and auto-approve if gas is available

**Kalshi (USDC on Solana):**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The checklist operationalizes auto-approval as a readiness requirement, normalizing autonomous permission grants as part of standard deployment. This encourages insecure default behavior in an environment with real-money transactions.

Content

Scanner excerpt · skill.md (reported line 756)May include surrounding context.

md
- [ ] `get_me()` returns valid agent info
- [ ] Polymarket CLOB credentials derived from private key and registered via `register_wallet_credentials()`
- [ ] automatic balance, gas/fees, and allowance checks are part of the trading flow
- [ ] missing allowance is auto-approved when technically possible
- [ ] Risk limits configured via `update_settings()`
- [ ] Heartbeat loop (`get_briefing()`) running or planned
- [ ] Error handling wraps every SDK call with `ApiError`

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skill.md:277