grimoire-polymarket

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for Polymarket trading, but it enables autonomous financial actions and routes private keys/API credentials through wrapper and CLI tooling. No clear exfiltration or deception is shown, yet the credential sensitivity and trading capability make the overall security risk high.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 3, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/franalgaba%2Fgrimoire%2Fgrimoire-polymarket%2F@9b15203e255ce635218ab00386da227a519762c9