polymarket

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The trading purpose broadly matches the capabilities, but the actual footprint is disproportionate: it installs an unverifiable binary from a different publisher than the declared source, forwards trading credentials to that binary, installs extra skills transitively, and sends device-fingerprinting telemetry to third-party endpoints. Because an unverifiable binary receives credentials, this is high security risk even without proof of outright malware.

Confidence: 90%Severity: 89%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fpolymarket%2F@45996cc6ce8958d6fca7e93e77abcd40adf9d5ca