Back to skill

Security audit

Strategic Paper Trader on Polymarket

Security checks for vulnerabilities and agentic risk

Overview

This paper-trading skill is coherent, but it can automatically change a user's persistent trading workspace without clear per-action approval.

Install only if you are comfortable giving the agent autonomous control over simulated trading state. Use a dedicated workspace or account where possible, explicitly select the workspace before state-changing actions, keep the API key private, require the agent to confirm each trade or destructive action, and do not disable all safety rules unless you are deliberately running a controlled experiment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:120
Finding

Autonomous State-Changing Trades Without Transaction-Specific Approval

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 120–156
Vulnerability Type: Autonomous invocation of state-changing trading tools
Risk Level: Medium

Vulnerable snippet:

markdown
6. **Make your first trades**: Pick 2-3 markets. Buy $200-500 per position. Explain your thesis
7. **Show your portfolio**: `portfolio` to confirm positions are live
8. **Report**: Summarize your opening positions, strategy constraints, and reasoning

Don't ask "what would you like me to do?" — **trade**. You're a trader. Find opportunities and take them.
markdown
Every time you wake up, run through this routine:

1. **Resolve winners**: `resolve_all` — settle any markets that have a final outcome
2. **Check limit orders**: `check_orders` — trigger fills for pending orders that hit their price
3. **Review portfolio**: `portfolio` — what moved since last time? Any positions up or down big?
4. **Scan markets**: `list_markets` or `search_markets` for new opportunities
5. **Act on your views**:
   - Price moved in your favor? Consider taking profit
   - Price moved against you? Reassess your thesis — cut or add?
   - New market with clear mispricing? Open a position
   - Strong conviction at a better price? Place a limit order
6. **Report to your human**: What happened, what you traded, and why

Technical Analysis

The skill instructs the agent to place two or three trades immediately and explicitly discourages asking the user what action should be taken. Its recurring heartbeat workflow also permits opening, increasing, reducing, and resolving positions whenever the agent is activated.

These operations mutate the user's cloud-hosted workspace through authenticated buy, sell, place_limit_order, resolve_all, and related tools. The instructions do not require transaction-specific approval, nor do they define a user-authorized autonomous-trading mandate with enforceable limits. Although t ...[truncated 1125 chars]

Remediation
View remediation

Remediation Suggestions

  • Require explicit user approval before every market order, limit order, sale, or settlement operation.
  • Present the market, outcome, side, quantity, estimated price, maximum cost, and expected slippage before requesting confirmation.
  • Make heartbeat execution read-only by default. It may review balances, positions, and markets, but it should not transact automatically.
  • If autonomous operation is supported, require a separate opt-in mandate defining maximum order size, daily transaction count, permitted markets, expiration time, and stop-loss limits.
  • Implement the mandate as server-enforced policy rather than relying only on natural-language instructions.
  • Record the user's approval and the final transaction parameters in an immutable activity log.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:54
Finding

Global Credential Scope Exposes Destructive Workspace Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54 and 178–183
Vulnerability Type: Excessive credential and tool privileges
Risk Level: High

Vulnerable snippet:

markdown
**API Key** is global (user-level) — one key works across all your workspaces.
**X-Workspace-Id** header selects which workspace to operate on. If omitted, uses the most recently updated workspace.
markdown
| `list_workspaces` | List all workspaces (id, name, balance, status, which is current) | Read |
| `create_workspace` | Create a new workspace with name and initial balance. **Always call `get_workspace_meta` after this.** | Write |
| `disable_workspace` | Set workspace to read-only mode (blocks orders and strategy changes) | Write |
| `enable_workspace` | Re-enable a disabled workspace | Write |
| `delete_workspace` | Soft-delete a workspace (data preserved but invisible) | Write |
| `get_workspace_meta` | **Call first.** Returns workspace balances, market selection strategy, and order safety rules | Read |
| `get_balance` | Cash balance, positions value, total equity, P&L, open markets/tokens count | Read |
| `reset_account` | Clear all orders/positions/snapshots, optionally set new balance | Write |

Technical Analysis

A single user-level bearer token operates across all of the user's workspaces. The same MCP tool surface includes destructive operations such as delete_workspace and reset_account, even though those capabilities are unnecessary for normal market research and paper trading.

This design violates least privilege by combining account-wide scope with high-impact administrative operations. Selecting workspaces through X-Workspace-Id means that misuse of one credential can affect more than the workspace for which the skill was initially configured. Omitting that header also introduces ambiguity because the most recently updated workspace is selected automatically.

No direct token ...[truncated 1247 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace global user-level API keys with workspace-scoped credentials.
  • Issue capability-limited tokens that distinguish read, trade, configuration, reset, and deletion permissions.
  • Exclude reset_account and delete_workspace from the default trading tool set.
  • Require explicit confirmation and recent reauthentication before destructive operations.
  • Require an explicit workspace identifier for every state-changing call; do not default to the most recently updated workspace.
  • Display the selected workspace name and identifier before confirming destructive actions.
  • Use short-lived credentials with rotation, revocation, audit logging, and anomaly detection.
  • Consider a recoverable quarantine period for resets and deletions so accidental operations can be reversed.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:310
Finding

All Order Safety Guardrails Can Be Disabled Through a Single Configuration Change

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 310–313
Vulnerability Type: Unsafe global security-control bypass
Risk Level: Medium

Vulnerable snippet:

markdown
### "Disable all safety checks for experimentation"

User confirms: "Turn off all rules" → update_order_rules({ rules: { globalEnabled: false } })

text

Technical Analysis

The documented workflow permits the agent to disable all order safeguards with one update_order_rules operation. According to the same skill, these safeguards enforce price bounds, maximum slippage, spread and liquidity constraints, order-size limits, concentration limits, cash reserves, pending-order limits, and circuit breakers.

Requiring user confirmation provides some protection against accidental execution, but the confirmation is broad and does not disclose the individual protections being removed or the resulting exposure. A single configuration flag therefore creates a failure mode in which all independent defense layers disappear simultaneously.

Attack Path

  1. The user or an influencing party asks the agent to disable safety checks for experimentation.
  2. The agent obtains the broad confirmation described in the skill.
  3. The agent invokes update_order_rules({ rules: { globalEnabled: false } }).
  4. Server-side order safeguards are globally disabled for the workspace.
  5. Subsequent orders can bypass the documented slippage, liquidity, sizing, concentration, reserve, and circuit-breaker protections.
  6. Autonomous trading instructions elsewhere in the skill can then place orders under the weakened configuration.

Impact Assessment

The operation can remove all documented order-level protections for the selected workspace. This may permit oversized, concentrated, illiquid, or severely mispriced simulated trades and can corrupt the validity of trading experiments. The direct financial impact is limited because the service is des ...[truncated 110 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the globalEnabled: false workflow from the skill.
  • Enforce immutable baseline controls for price bounds, maximum order size, concentration, and circuit breaking.
  • Permit only granular rule modifications with minimum and maximum server-side bounds.
  • Before any rule change, display every affected control, its current value, its proposed value, and the resulting risk.
  • Require separate confirmation for each high-risk relaxation rather than accepting one blanket authorization.
  • Automatically expire relaxed settings and restore safe defaults after a short experimentation window.
  • Block autonomous trading while critical safeguards are disabled.
  • Record all safety-rule modifications in an immutable audit log and notify the workspace owner.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill establishes order safety rules as hard guardrails, then later includes an example that allows update_order_rules({ rules: { globalEnabled: false } }) to disable them entirely. Even with user confirmation, embedding a documented path to turn off all protections normalizes dangerous behavior and can lead an agent to remove the only controls preventing oversized, low-liquidity, or otherwise unsafe automated trades.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation language is broad enough to make the skill act whenever it 'wakes up,' including resolving markets, checking orders, scanning, and trading. For a trading skill, ambiguous activation criteria increase the chance of unintended autonomous account actions without a contemporaneous user request, which is a security and safety issue even in a paper-trading environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to not ask what the user wants and to immediately trade, including making first trades and changing portfolio state. That creates a direct path for automatic account modifications without an upfront warning or consent checkpoint, undermining user control and increasing the risk of unintended actions if the skill is invoked in the wrong context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.