Back to skill

Security audit

Polymarket Temperature Event Follower

Security checks for vulnerabilities and agentic risk

Overview

This is a real-money Polymarket trading bot with disclosed trading and billing behavior, but it has serious credential-handling and trade-integrity issues that warrant Review before installation.

Review this skill carefully before installing or running it. Do not use a primary wallet, avoid live mode until the threshold logic and credential handling are fixed, treat any credentials printed in logs as exposed, and run only in an isolated environment with pinned dependencies and a tightly funded dedicated wallet.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
sniper-en.py:82
Finding

Hardcoded SkillPay API Credential Exposed in Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
sniper-en.py:845
Finding

Polymarket L2 Trading Credentials Disclosed Through Console Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:5
Finding

Unpinned Security-Critical Dependencies Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
sniper-en.py:786
Finding

Reversed Entry-Threshold Comparison Can Trigger Unintended Live Trades

Content
View full analysis
= ENTRY_THRESHOLD: tradeable.append(outcome) print(f"[SCAN] Tradeable events (best_ask >= {ENTRY_THRESHOLD}): {len(tradeable)}") return tradeable, selected, enriched ``` The declared strategy says the opposite: ```text When YES token price is below 0.35, consider market underestimating "high temp" probability ``` `SKILL-en.md:313` likewise states: ```text Entry threshold. Buy only if YES token price < this ``` ### Technical Analysis The implementation marks an outcome tradeable when `best_ask` is greater than or equal to `ENTRY_THRESHOLD`, while the documented strategy requires the price to be lower than the threshold. The selected candidate is later passed to live order execution, where `py-clob-client` signs and submits a GTC buy order. Consequently, the error is not limited to reporting or simulation: when `--live` is enabled, it can authorize real financial transactions outside the represented strategy. The separate `max_price` calculation does not correct the reversed strategy condition because it is derived from the already selected market price. It provides relative slippage control, not enforcement of the documented absolute entry ceiling. ### Attack Path 1. A user configures `ENTRY_THRESHOLD=0.35` based on the documentation. 2. A market presents a YES best ask at or above `0.35`. 3. The reversed `>=` comparison adds that market to the tradeable set. 4. The trading loop passes the selected token and price to `execute_buy_order()`. 5. In live mode, the program creates a signed order and calls `client.post_order(...)`. 6. The user acquires a position that should have been rejected under the docu ...[truncated 691 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (84)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-en.md (reported line 74)May include surrounding context.

md
pip install -r requirements.txt

# 3. Copy environment template
copy .env.example .env
# Then edit .env file and fill in your keys (see Section 4)

# 4. Test run (simulation mode, no real money)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL-en.md (reported line 608)May include surrounding context.

md
---

### 9.3 Reset State

Delete `state.json` and `cache/` directory:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is supported by the documentation's instructions to run live mode to obtain credentials and by references to external SkillPay billing APIs, while no permissions or security boundaries are declared. In a trading skill, undisclosed secret handling and external charging are especially dangerous because they can directly lead to account compromise, unauthorized charges, or irreversible market orders.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is supported by the documentation's instructions to run live mode to obtain credentials and by references to external SkillPay billing APIs, while no permissions or security boundaries are declared. In a trading skill, undisclosed secret handling and external charging are especially dangerous because they can directly lead to account compromise, unauthorized charges, or irreversible market orders.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
创建 `requirements.txt` 文件(如果不存在):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-en.md (reported line 515)May include surrounding context.

bash
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore

# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..."  # 不要这样!

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

bash
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore

# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..."  # 不要这样!

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 1222)May include surrounding context.

python
```bash
# ✅ 正确:.env 文件加入 .gitignore
echo ".env" >> .gitignore

# ❌ 错误:不要硬编码在代码里
PRIVATE_KEY="0x..."  # 不要这样!

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-en.md (reported line 75)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-en.md (reported line 438)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL-en.md (reported line 514)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 414)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 490)May include surrounding context.

md
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · requirements.txt (reported line 12)May include surrounding context.

text
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 146)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 154)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 427)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 428)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper-en.py (reported line 449)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper.py (reported line 146)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper.py (reported line 154)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper.py (reported line 449)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sniper.py (reported line 1222)May include surrounding context.

python
pytz          # 时区支持(城市时间转换)

# 环境配置
python-dotenv    # 从 .env 文件加载配置

# 区块链交互
eth-account     # 以太坊钱包私钥处理、签名

Static analysis

No suspicious patterns detected.