polymarket-paper-trader

Fail

Audited by Socket on Mar 9, 2026

2 alerts found:

Obfuscated FileAnomaly
Obfuscated FileHIGH
SKILL.md

The Polymarket Paper Trading Engine is coherent with its stated purpose: it simulates trading using live prices in a risk-free environment with local persistence. Network data flows are expected (live price data), and storage is limited to a local SQLite database; there are no evident credential or binary download patterns. Overall risk is low to moderate, primarily tied to reliance on external market data integrity and local data protection. Recommend monitoring for any future features that introduce external auth tokens, unverified binaries, or data exfiltration vectors beyond the described simulation scope.

Confidence: 98%
AnomalyLOW
scripts/paper_engine.py

The fragment appears to be a market-trading simulation tool with standard data flows for inputs, API calls, and DB persistence. There is no clear evidence of intentional malware, backdoors, or data exfiltration beyond expected API usage and local data storage. The primary concerns are structural issues (syntactic placeholders, broken SQL calls) that would prevent execution and could mask malicious edits in a real package. If this were a dependency, it would warrant a deeper review of the actual SQL statements and any hardcoded secrets, along with ensuring secure handling of API interactions and robust input validation.

Confidence: 59%Severity: 55%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:22 PM
Package URL
pkg:socket/skills-sh/mjunaidca%2Fpolymarket-skills%2Fpolymarket-paper-trader%2F@eae3f0474aa264915a8b6d07893f1a2ae926661f