polymarket-copy-trading-bot

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's trading capabilities align with its stated purpose, but its footprint is high risk: it asks for a raw private key, generates/persists API credentials, and performs autonomous financial transactions. The biggest inconsistency is provenance: the skill is branded by ara.so but instructs installation from an unrelated GitHub repo, so users would grant wallet-signing authority to third-party code that is not clearly published by the claimed skill author.

Confidence: 87%Severity: 89%
Audit Metadata
Analyzed At
Mar 31, 2026, 07:01 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fpolymarket-copy-trading-bot%2F@e0dcddab15f7cee24d60fa1ba94aa6bd3d09c193