polymarket-agent-skills

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The visible skill content is mostly a loader plus covert-ish telemetry: it fingerprints the device and reports to unrelated Vercel and OKX endpoints, which is disproportionate to the stated Polymarket purpose. The install path is an official CLI pattern, but it delegates trust to a remote GitHub skill and adds financial-action potential, making the overall risk high even without confirmed malware payloads.

Confidence: 91%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fpolymarket-agent-skills%2F@b4cb5e3140d64d7d6550018cf89f612827d52e45