T09 · Insecure Skill Coding Practices
- Location
sniper-en.py:82- Finding
Hardcoded SkillPay API Credential Exposed in Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real-money Polymarket trading bot with disclosed trading and billing behavior, but it has serious credential-handling and trade-integrity issues that warrant Review before installation.
Review this skill carefully before installing or running it. Do not use a primary wallet, avoid live mode until the threshold logic and credential handling are fixed, treat any credentials printed in logs as exposed, and run only in an isolated environment with pinned dependencies and a tightly funded dedicated wallet.
sniper-en.py:82Hardcoded SkillPay API Credential Exposed in Source Code
sniper-en.py:845Polymarket L2 Trading Credentials Disclosed Through Console Output
requirements.txt:5Unpinned Security-Critical Dependencies Create Supply-Chain Exposure
sniper-en.py:786Reversed Entry-Threshold Comparison Can Trigger Unintended Live Trades
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install -r requirements.txt
# 3. Copy environment template
copy .env.example .env
# Then edit .env file and fill in your keys (see Section 4)
# 4. Test run (simulation mode, no real money)
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
---
### 9.3 Reset State
Delete `state.json` and `cache/` directory:
This finding is supported by the documentation's instructions to run live mode to obtain credentials and by references to external SkillPay billing APIs, while no permissions or security boundaries are declared. In a trading skill, undisclosed secret handling and external charging are especially dangerous because they can directly lead to account compromise, unauthorized charges, or irreversible market orders.
This finding is supported by the documentation's instructions to run live mode to obtain credentials and by references to external SkillPay billing APIs, while no permissions or security boundaries are declared. In a trading skill, undisclosed secret handling and external charging are especially dangerous because they can directly lead to account compromise, unauthorized charges, or irreversible market orders.
Referenced artifact was not completely inspected
创建 `requirements.txt` 文件(如果不存在):
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore
# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..." # 不要这样!
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore
# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..." # 不要这样!
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```bash
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore
# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..." # 不要这样!
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pytz # 时区支持(城市时间转换)
# 环境配置
python-dotenv # 从 .env 文件加载配置
# 区块链交互
eth-account # 以太坊钱包私钥处理、签名
No suspicious patterns detected.