Back to skill

Security audit

pmbuysell-polymarket

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Polymarket trading skill, but it needs review because it can place real-money orders and has weak safeguards for transaction amounts, credentials, and dependencies.

Install only after reviewing it as live financial software. Use a dedicated wallet with limited funds, require human confirmation for every trade, avoid relying on amount=0 or negative/sentinel amounts, pin and audit dependencies, and protect or disable plaintext credential caching where possible. Do not install the separate redeem add-on without reviewing that package independently.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
polymarket_client.py:212
Finding

Non-positive trade amounts can trigger unintended large transactions

Content
View full analysis
= 1000: amount = balance_conditional order = MarketOrderArgs(token_id=token_id, amount=amount, side=SELL, order_type=OrderType.FOK) ``` ### Technical Analysis The CLI parses `--amount` as a floating-point numb ...[truncated 2538 chars]
Remediation
View remediation
balance_conditional: raise ValueError("sell amount exceeds the available position") else: raise ValueError("unsupported action") ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
polymarket_client.py:36
Finding

Derived Polymarket API credentials are stored in plaintext files

Content
View full analysis
Path: s = (funder or "").strip().lower() try: _DATA_DIR.mkdir(parents=True, exist_ok=True) except Exception: return _PMBUYSELL_DIR / "polymarket_api_creds_fallback.json" if not s: return _DATA_DIR / "polymarket_api_creds_unknown.json" tail = s[-8:].replace("0x", "") h = hashlib.sha1(s.encode("utf-8")).hexdigest()[:10] return _DATA_DIR / f"polymarket_api_creds_{tail}_{h}.json" ``` ```python # polymarket_client.py:49-61 def _load_api_creds_cache(cache_path: Path) -> Optional[dict]: if not cache_path.exists(): return None try: with cache_path.open("r", encoding="utf-8") as f: return json.load(f) except Exception: return None def _save_api_creds_cache(cache_path: Path, api_creds: ApiCreds) -> None: try: with cache_path.open("w", encoding="utf-8") as f: json.dump(asdict(api_creds), f, indent=2) except Exception: pass ``` ```python # polymarket_client.py:133-151 cache_path = _api_creds_cache_path(self.funder) cached = _load_api_creds_cache(cache_path) if cached: try: creds = ApiCreds( api_key=cached["api_key"], api_secret=cached["api_secret"], api_passphrase=cached["api_passphrase"], ) client.set_api_creds(creds) except (KeyError, TypeError): cached = None if not cached: api_creds = client.create_or_derive_api_creds() client.set_api_creds(api_creds) _save_api_creds_cache(cache_path, api_creds) ``` ### Technical Analysis The client serializes the complete `ApiCreds` object, including the API key, API secret, and API passphrase, into an un ...[truncated 2169 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Security-sensitive dependencies are installed without version or integrity constraints

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented as a trading/query interface, but it also initializes and may overwrite local configuration files by generating a .env template. Writing configuration files to disk is a materially different capability from querying balances or placing orders, and in an agent context it can modify local state in ways the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a trading/query interface, but it also initializes and may overwrite local configuration files by generating a .env template. Writing configuration files to disk is a materially different capability from querying balances or placing orders, and in an agent context it can modify local state in ways the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly depends on reading account identifiers and private-key/funder configuration from .env, which confirms access to sensitive credentials as part of normal operation. In the context of a live trading skill, credential access is expected but still dangerous because compromise or misuse enables unauthorized trades and potential financial loss.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| 参数 | 必填 | 说明 |
|------|------|------|
| `--account` | 是 | 账号 ID,如 ACC1(需在 .env 的 PM_ACCOUNT_IDS 及 ACC1_PRIVATE_KEY/ACC1_FUNDER 中配置) |
| `--action` | 是 | `buy` 或 `sell` |
| `--slug` | 手动时必填 | 市场 slug,如 `tc-updown-5m-1772452800` |
| `--slug-mode` | 否 | `manual`(默认)或 `auto`;auto 时用 `--symbol`、`--timeframe` 生成当前桶 slug |

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The checklist reinforces that the skill relies on .env-stored account configuration, indicating operational dependence on local secret material. While this reference alone does not prove exfiltration, it does confirm credential handling in an agent workflow, which raises risk if permissions and safeguards are not explicit.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
## 模型调用检查清单

1. 确认在 **项目根目录** 下执行 CLI,或当前环境能 `import pmbuysell`。
2. 确认 `account` 已在 .env 中配置。
3. 手动 slug 时:`slug` 格式为 `{symbol}-updown-{5m|15m}-{桶起始时间戳}`。
4. 自动 slug 时:只支持 `timeframe` 为 `5m` 或 `15m`。
5. 根据返回的 `ok` 与 `message` 判断是否成功;失败时 `message` 常含余额、市场关闭、无匹配等提示。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · FEATURES.md (reported line 27)May include surrounding context.

md
def _minimal_env_template() -> str:
    return "\n".join(
        [
            "# pmbuysell .env (generated)",
            "# 账号配置(二选一:推荐用 PM_ACCOUNT_IDS + ACCx_*)",
            "PM_ACCOUNT_IDS=ACC1",
            "ACC1_PRIVATE_KEY=0xYOUR_PRIVATE_KEY",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · init_cli.py (reported line 22)May include surrounding context.

python
def _minimal_env_template() -> str:
    return "\n".join(
        [
            "# pmbuysell .env (generated)",
            "# 账号配置(二选一:推荐用 PM_ACCOUNT_IDS + ACCx_*)",
            "PM_ACCOUNT_IDS=ACC1",
            "ACC1_PRIVATE_KEY=0xYOUR_PRIVATE_KEY",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · init_cli.py (reported line 48)May include surrounding context.

python
def _minimal_env_template() -> str:
    return "\n".join(
        [
            "# pmbuysell .env (generated)",
            "# 账号配置(二选一:推荐用 PM_ACCOUNT_IDS + ACCx_*)",
            "PM_ACCOUNT_IDS=ACC1",
            "ACC1_PRIVATE_KEY=0xYOUR_PRIVATE_KEY",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · init_cli.py (reported line 53)May include surrounding context.

python
_PROJECT_DIR = _PMBUYSELL_DIR.parent                     # .../pm (project root for our usage)

_ENV_PATHS = [
    _PMBUYSELL_DIR / ".env",  # preferred
    _PROJECT_DIR / ".env",    # optional fallback (compatible with older layouts)
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local_config.py (reported line 26)May include surrounding context.

python
_PROJECT_DIR = _PMBUYSELL_DIR.parent                     # .../pm (project root for our usage)

_ENV_PATHS = [
    _PMBUYSELL_DIR / ".env",  # preferred
    _PROJECT_DIR / ".env",    # optional fallback (compatible with older layouts)
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · local_config.py (reported line 27)May include surrounding context.

python
_PROJECT_DIR = _PMBUYSELL_DIR.parent                     # .../pm (project root for our usage)

_ENV_PATHS = [
    _PMBUYSELL_DIR / ".env",  # preferred
    _PROJECT_DIR / ".env",    # optional fallback (compatible with older layouts)
]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The feature list advertises market trading and auto-redeem actions for AI agents without any explicit warning that these operations can move real funds, incur losses, or be irreversible once submitted on the platform. In an agent-skill context, omission of such warnings increases the chance of unsafe autonomous execution or accidental financial loss by users who may treat the skill as a routine utility.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that access environment variables, read/write local files, and perform network-backed trading operations, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, missing scope declarations can cause the skill to be invoked with broader privileges than users expect, increasing the chance of unintended credential access or real-money actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation provides direct instructions for live trading and balance operations without a prominent warning that these commands can trigger real financial transactions and irreversible losses. In the context of a trading skill, lack of explicit risk disclosure makes accidental execution significantly more dangerous than in a non-financial domain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example one-click CLI commands are immediately executable and do not warn that configured credentials can be used to place real buy/sell orders. Because the examples are copy-paste ready, an agent or user could invoke them verbatim and cause unintended market exposure or loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration section includes private-key variables and example .env handling without warning that these are highly sensitive secrets that can authorize asset transfers or trading. In a financial skill, normalizing raw private-key placement in docs without strong handling guidance materially increases the risk of credential leakage and account compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code includes multiple natural-language strings shown to users, such as error messages and argument help text, entirely in Chinese. Under the policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes this skill as executing Polymarket trades and querying balances/positions, and explicitly says auto-redeem is a separate paid addon. This module nevertheless includes configuration accessors for automatic buy thresholds and auto-redeem dry-run behavior, which indicates support for automation/redeem-related behavior outside the stated core scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The returned message is hardcoded in Chinese, which imposes a specific language on users without opt-in. The file does not indicate that the skill is intentionally region- or language-specific, nor does it offer an alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This error message is presented only in Chinese, which can violate language/locale policy when users are not given a choice. No justification or locale constraint is documented in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code submits buy/sell trades through bot.trade_with_retry, which is a safety-critical and potentially irreversible financial operation. The file contains no confirmation prompt, print/log disclosure, or explanatory comment/docstring warning users that invoking this function can place real trades on an account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The success message is fixed to Chinese and does not provide any mechanism for locale selection. That creates a language policy concern unless the skill is explicitly documented as Chinese-only for a justified reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This returned error text is only in Chinese, forcing a language choice on all users. The file does not provide opt-in localization or explain a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code persists Polymarket API credentials to a JSON file on disk without any access-control hardening, encryption, or user disclosure. Because this skill performs live trading, compromise of the local filesystem, backups, logs, or shared workspace could expose credentials that enable unauthorized trading or account access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trade error messages returned to users are written in Chinese, and validation/error strings elsewhere in the file also use Chinese. The file does not offer locale selection or explain that the skill is intentionally Chinese-only, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The client creates and posts buy orders, including market FOK orders, which can spend user funds and are potentially irreversible once executed. In this file there is no confirmation prompt, visible log/print disclosure, or explanatory warning comment/docstring around order submission despite the destructive financial effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.