Back to skill

Security audit

Polymarket Politics Random Buyer

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed automated trading template, but it includes an undocumented redemption action and scheduled financial authority that deserve manual review before use.

Review carefully before installing. Use only a dedicated low-balance wallet and scoped API key, do not enable live scheduled runs until the redemption behavior is documented and gated, avoid --auto-redeem unless you understand its SDK effects, and prefer pinned dependencies or a locked environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:4
Finding

Unpinned Security-Sensitive Third-Party Dependencies

Content
View full analysis

Vulnerability Details

File Location: clawhub.json, lines 4-6
Vulnerability Type: Supply-chain risk from unconstrained dependencies
Risk Level: Medium

Vulnerable Code

json
"requires": {
  "pip": ["aion-sdk", "python-dotenv", "eth-account"],
  "env": ["AION_API_KEY", "WALLET_PRIVATE_KEY"]
},

Technical Analysis

The project declares aion-sdk, python-dotenv, and eth-account without exact version constraints or integrity hashes. Each installation may therefore resolve to a different package release. This weakens build reproducibility and permits newly published, compromised, or unexpectedly incompatible releases to execute without a corresponding change to the audited project.

The exposure is particularly significant because these dependencies execute in a process containing an AION API key and a wallet private key. The SDK also controls market-context requests, auto-redemption, and live trade submission. Python imports execute package initialization code, so a compromised resolved dependency could access environment variables or alter transaction behavior immediately.

The audit found no evidence that the package names themselves are typosquatted or currently malicious. The finding concerns the absence of version and integrity controls.

Attack Path

  1. An attacker compromises the publishing account, distribution pipeline, or upstream source of one of the declared packages.
  2. The attacker publishes a malicious release under the legitimate package name.
  3. A later installation resolves the unconstrained package requirement to that release.
  4. The malicious package executes during installation or import.
  5. It reads AION_API_KEY, AIONMARKET_API_KEY, or WALLET_PRIVATE_KEY from the process environment, or modifies SDK operations.
  6. The attacker can then misuse stolen credentials or manipulate live financial actions within the authority of those credentials.

Impact Asse

...[truncated 561 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every production dependency to a reviewed exact version rather than accepting the latest available release.
  2. Generate a lock file containing transitive dependency versions.
  3. Require package hashes during installation, such as with a hash-locked requirements file and pip --require-hashes.
  4. Install exclusively from a trusted, explicitly configured package index.
  5. Scan direct and transitive dependencies for known vulnerabilities before release and installation.
  6. Use an isolated virtual environment and prevent dependency installation at runtime.
  7. Review new versions before updating pins, with particular attention to aion-sdk because it mediates account and trade operations.
  8. Minimize secret exposure by providing credentials only to the final runtime process and using a narrowly funded, least-privileged wallet.

T09 · Insecure Skill Coding Practices

Warning
Location
politics_random_buyer.py:354
Finding

Auto-Redemption Executes Outside the Advertised Live-Mode Boundary

Content
View full analysis

Vulnerability Details

File Location: politics_random_buyer.py, lines 354-359
Vulnerability Type: Undocumented state-changing operation in dry-run mode
Risk Level: Medium

Vulnerable Code

python
wallet_address = derive_wallet_address()
client = get_client()

if args.auto_redeem:
    client.auto_redeem()

The trade-specific live-mode check occurs later at lines 382-385:

python
if not args.live:
    print("\nDry-run only. Re-run with --live to execute the trade.")
    return 0

Technical Analysis

The script advertises dry-run as its default and requires --live before calling client.trade(). However, the separately parsed --auto-redeem option invokes client.auto_redeem() before that live-mode guard.

As a result, python politics_random_buyer.py --auto-redeem can initiate an SDK account operation even though args.live is false and the script subsequently reports that it is “Dry-run only.” The --auto-redeem option and its effects are also absent from SKILL.md.

The exact on-chain or account-side behavior of AionClient.auto_redeem() is implemented by the external SDK and was not present in the audited repository. The audit therefore does not assert undocumented implementation details. Nonetheless, the method name and placement establish that this operation is not protected by the script's explicit live-trading boundary.

Attack Path

  1. An operator or automation invokes the skill with --auto-redeem but without --live, believing that the default mode prevents externally consequential operations.
  2. The script loads the API credential, derives the wallet address, and initializes the AION client.
  3. It calls client.auto_redeem() immediately because args.auto_redeem is true.
  4. Only after market discovery and selection does execution reach the if not args.live check.
  5. The script prints a dry-run message and exits, despite having already requested ...[truncated 759 chars]
Remediation
View remediation

Remediation Suggestions

  1. Place every state-changing SDK operation behind the same explicit live-mode guard.

  2. Reject --auto-redeem unless --live is also present:

    python
    if args.auto_redeem and not args.live:
        raise SystemExit("--auto-redeem requires --live")
    
    if args.live and args.auto_redeem:
        client.auto_redeem()
    
  3. Prefer a separate redemption command so trade simulation and account maintenance cannot be confused.

  4. Require an additional explicit confirmation option for unattended redemption, especially when managed scheduling is enabled.

  5. Document --auto-redeem, its external effects, fee implications, permissions, and interaction with dry-run mode in SKILL.md.

  6. Change the output so “Dry-run only” is printed only when no state-changing operation has occurred.

  7. Add tests asserting that neither client.trade() nor client.auto_redeem() is called without the required live-mode authorization.

  8. Record structured audit logs for all attempted and completed account-changing operations.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · politics_random_buyer.py (reported line 26)May include surrounding context.

python
SKILL_SLUG = "polymarket-politics-random-buyer"
TRADE_SOURCE = f"sdk:{SKILL_SLUG}"
VENUE = "polymarket"
ENV_PATH = Path(__file__).with_name(".env")
DEFAULT_QUERIES = ["election", "president", "senate", "house", "governor", "politics"]
POLITICS_KEYWORDS = {
    "election",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation declares that the script requires sensitive environment secrets such as an API key and a wallet private key, but it does not define an explicit tool scope or permissions boundary for environment access. In an agent ecosystem, this weakens least-privilege guarantees and can allow broader secret exposure than operators expect, which is especially risky because the skill is capable of initiating live trades with financial consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly requires a wallet private key and describes automated context-aware trading, but it does not present any clear user-facing warning that the skill can place real trades on a schedule and may cause irreversible financial loss. In this context, the omission is meaningful because the skill is configured to run every 30 minutes and defaults to buying positions, which increases the chance of users enabling live trading without fully understanding the risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill that randomly finds a politics market, checks context, and buys 1 USDC with dry-run/live modes. However, the code adds an --auto-redeem capability, which performs a separate account-affecting action unrelated to selecting and buying a market.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code invokes client.auto_redeem() even though the skill is described primarily as a random market buyer. That mismatch can mislead users and downstream agents into authorizing broader account actions than expected, increasing the chance of unintended position settlement or account-side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

client.auto_redeem() executes immediately when --auto-redeem is set, with no confirmation prompt, preview, or summary of affected positions. For a wallet-linked trading skill, this creates a real risk of unintended irreversible account actions if the flag is passed by mistake or injected through automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.