polygon-discovery

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s payment-gateway purpose is coherent, but its footprint is high risk because it routes many unrelated services through a third-party Render-hosted API and enables automatic wallet-funded transactions. The main concern is autonomous spending plus external processing of potentially sensitive code and text, not confirmed malware.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
May 1, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/0xpolygon%2Fpolygon-agent-cli%2Fpolygon-discovery%2F@7e87426b5be428bb234eff02b370f08c56b90156