Back to skill

Security audit

Weather Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a real-money weather trading skill with disclosed core purpose, but its effective trading limits and local code-loading behavior are too broad for automatic trust.

Install only if you understand it can place real USDC trades and you are comfortable auditing the effective config first. Use a minimally scoped SIMMER_API_KEY, avoid running --live or --no-safeguards until defaults are corrected, pin simmer-sdk, and do not run this in a shared skill directory where sibling files could influence imports.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Warning
Location
clawhub.json:5
Finding

Unpinned Trading SDK Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
weather_trader.py:94
Finding

Parent-Directory Module Preloading Allows Local Tool Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trade_performance.py:876
Finding

Path Traversal in Auto-Tune Option Can Execute an Arbitrary Local Python Module

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:2
Finding

Shipped Trading Configuration Weakens Documented Financial Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The claimed weather-trading functionality is absent, while undeclared capabilities like trade logging, circuit breaker control, auto-tuning, and changelog/revert CLI are present. Undeclared control and logging features matter because they can affect local state and operator decisions in ways reviewers and users did not consent to or expect.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
71% confidence
Finding

The skill loads a project-root .env file automatically, which can unintentionally ingest secrets unrelated to this skill from a broader workspace. In multi-skill or shared environments, this expands secret exposure and makes it easier for imported modules or future code changes to access credentials that were never meant for this component.

Content

Scanner excerpt · weather_trader.py (reported line 30)May include surrounding context.

python
from urllib.error import HTTPError, URLError
from urllib.parse import urlencode

# Load .env from project root (two levels up from this file)
try:
    from dotenv import load_dotenv

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Resolving and loading ../../.env creates cross-boundary secret access: the skill reaches outside its own directory and imports all variables from a higher-level file. In shared repositories, that can expose unrelated API tokens or operational credentials to this trading skill and any modules it imports, increasing blast radius if the skill is compromised or behaves unexpectedly.

Content

Scanner excerpt · weather_trader.py (reported line 34)May include surrounding context.

python
try:
    from dotenv import load_dotenv

    _env_path = Path(__file__).resolve().parent.parent / ".env"
    if _env_path.exists():
        load_dotenv(_env_path)
except ImportError:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises capabilities that inherently require network, file, and environment access, but it does not declare an explicit tool/permission scope. In an agent setting, missing scope boundaries makes it harder to enforce least privilege and increases the chance that a trading-oriented skill gets broader access than intended, especially given its documented read/write logging and live trading behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents live real-money trading against Polymarket/USDC without a prominent warning that execution may be irreversible and financially risky. In a skill that can plausibly be invoked by non-experts, weak risk disclosure increases the likelihood of accidental fund loss or unintended live orders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Advertising a --no-safeguards option without an explicit, strong warning normalizes disabling protective controls in a real-money trading system. That raises the chance of users running with slippage, circuit-breaker, or other protections bypassed, which can materially increase loss and unstable behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest does not define any explicit trigger scope, allowed invocation conditions, or narrowing constraints beyond descriptive text. For a trading skill that can place market orders via an API key, ambiguous activation increases the risk of unintended invocation by loosely related prompts, which could lead to unauthorized or accidental trades.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text states that --snapshot controls whether a snapshot is written, but the program writes a snapshot even when that flag is absent because of the later 'if args.snapshot or not args.quiet' logic. This mismatch can mislead users and downstream tooling into triggering unintended writes, which is a security-relevant integrity issue even if it does not enable code execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs a filesystem write as part of normal reporting behavior, which violates the expected read-only semantics of a reporting utility. In this trading-skill context, silent mutation of local state can surprise operators, overwrite prior snapshots, and interfere with automation that assumes report generation is side-effect free.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes performance_snapshot.json during ordinary execution without explicit user opt-in or a clear warning, creating an unexpected persistent side effect. In a skill that may be run by agents or scheduled jobs, this can lead to unanticipated file creation, state drift, and overwriting of prior data, increasing operational risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The --auto-tune path constructs a sibling skill path from user-controlled input, then dynamically loads and executes that trader module via importlib. That means running this reporting utility can execute arbitrary Python code from any sibling skill directory, expanding the trust boundary from this weather skill to adjacent local content and creating a code-execution primitive if an attacker can place or influence such a module.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code automatically loads a project-root .env file and later consumes SIMMER_API_KEY for authenticated trading, which is a sensitive credential access path. Although the docstring lists the required variable, there is no runtime disclosure, confirmation, or warning that the skill will read credentials from local environment/.env sources before contacting trading APIs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes trading driven by NOAA and Open-Meteo forecasts, EV/Kelly sizing, Bayesian updates, and maker/taker switching. This file additionally fetches and merges external 'Smart Money' signals into trade decisions, which is a separate market-intelligence capability not declared in the stated purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather_trader.py (reported line 699)May include surrounding context.

python
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}

OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"

MAX_RETRIES = 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather_trader.py (reported line 700)May include surrounding context.

python
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}

OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"

MAX_RETRIES = 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather_trader.py (reported line 1194)May include surrounding context.

python
"Wuhan": {"lat": 30.5928, "lon": 114.3055, "tz": "Asia/Shanghai"},
}

OPEN_METEO_BASE = "https://api.open-meteo.com/v1/forecast"
OPEN_METEO_ENSEMBLE_BASE = "https://api.open-meteo.com/v1/ensemble"

MAX_RETRIES = 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather_trader.py (reported line 953)May include surrounding context.

python
if not station_id:
        return {}

    url = f"https://api.weather.gov/stations/{station_id}/observations/latest"
    headers = {
        "User-Agent": "SimmerWeatherSkill/1.0 (https://simmer.markets)",
        "Accept": "application/geo+json",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill can be used to configure locations/thresholds, and the code even loads a locations setting into ACTIVE_LOCATIONS. However, the main strategy always discovers broad weather markets and groups/trades all parsed events without filtering to configured locations, so configured locations do not actually constrain behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.