Back to skill

Security audit

Polymarket Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently fetches Polymarket market odds and can set up user-facing recurring alerts, with the main caution being ongoing cron-based Slack notifications.

Install only if you want an agent to make recurring Polymarket API checks and send Slack alerts. Before enabling monitoring, confirm the exact markets, threshold, check interval, Slack recipient, and how to remove the cron job.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code partially matches the declared description only in the narrow sense that it fetches current Polymarket odds. However, the declared purpose emphasizes monitoring markets, searching for them by topic, and generating threshold-based recurring alerts through channels like Slack. This script does none of those things: it performs a one-time fetch for explicitly provided condition IDs and prints results locally. The mismatch is due to missing core advertised functionality rather than undeclared dangerous behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to perform network access via curl, web_fetch, and external API calls, but it does not declare corresponding tool scope or permissions. This creates a transparency and least-privilege problem: the skill can cause outbound requests beyond what a reviewer or runtime policy may expect, increasing the risk of unintended data egress or misuse of networked capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description uses broad activation language such as monitoring any Polymarket market, recurring checks, and notifications across channels. Overbroad triggers can cause the skill to activate in more contexts than necessary, leading to unnecessary network access, scheduling of persistent tasks, or messaging actions when a narrower skill would have been more appropriate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill directs creation of a recurring cron job that runs in an isolated session and can continue making network requests and sending Slack DMs without further user interaction. Persistent autonomous execution increases the risk of spam, unintended monitoring, silent long-term external communication, and stale tasks continuing after user intent has changed.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
### 4. Set up the cron alert

Create a cron job that runs every N minutes (default: 30) with `sessionTarget: "isolated"` and `payload.kind: "agentTurn"`. The agent task should:

1. Fetch each market via `web_fetch` using the Gamma API (conditionId endpoint)
2. Parse `outcomePrices[0]` as the Yes probability

Static analysis

No suspicious patterns detected.