Back to skill

Security audit

Polymarket Divergence Trader

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed trading template, but it quietly installs a recurring managed run every 15 minutes for a financial workflow.

Install only if you are comfortable with a managed task running every 15 minutes. Use a restricted Simmer API key, keep live trading disabled unless you intentionally pass --live, verify or disable the cron automaton, and review dependency versions before use.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Warning
Location
clawhub.json:47
Finding

Undisclosed Managed Scheduled Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Unpinned Security-Sensitive Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
", "python-dotenv==" ] ``` 2. Use a hash-locked requirements file or equivalent lock format so installers verify package artifacts cryptographically. 3. Configure installation to use the official package index over authenticated TLS and reject unapproved alternate indexes. 4. Review package ownership, release history, transitive dependencies, and integrity before updating pinned versions. 5. Introduce automated dependency vulnerability and provenance scanning in the release process. 6. Run the skill with least privilege and provide an API key restricted to only the required market operations and spending limits. 7. Isolate the process from unrelated secrets and filesystem locations so a compromised dependency has minimal access. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · divergence_trader.py (reported line 22)May include surrounding context.

python
SKILL_SLUG = "polymarket-divergence-trader"
TRADE_SOURCE = f"sdk:{SKILL_SLUG}"
ENV_PATH = Path(__file__).with_name(".env")
DRY_RUN_VENUE = "sim"
DEFAULT_LIVE_VENUE = "polymarket"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation declares required environment-based inputs such as SIMMER_API_KEY but does not define any explicit tool scope or permission boundaries. In an agent ecosystem, this can lead to overbroad environment access, making it easier for the skill implementation to read secrets beyond what is strictly needed or for operators to misunderstand its privilege requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The CLI allows --live-venue values of polymarket, kalshi, or sim, while the stated skill purpose says optional live execution on Polymarket. This scope expansion can cause trades on an unintended real-money venue if operator assumptions, automation wrappers, or environment defaults are based on the manifest, increasing the chance of misdirected execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for trading markets based on probability divergence, with dry-run and optional live execution. Adding an --auto-redeem path introduces a separate account-management/post-trade settlement action that goes beyond deciding and placing a divergence trade, and this extra capability is not mentioned in the skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.