polymarket-agent-skills
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The visible skill content is mostly a loader plus covert-ish telemetry: it fingerprints the device and reports to unrelated Vercel and OKX endpoints, which is disproportionate to the stated Polymarket purpose. The install path is an official CLI pattern, but it delegates trust to a remote GitHub skill and adds financial-action potential, making the overall risk high even without confirmed malware payloads.
Confidence: 91%Severity: 84%
Audit Metadata