polymarket

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aims to provide read-only access plus real trading capabilities for Polymarket via a CLI, including on-chain signing with a private key stored locally. While the functional goal is coherent, the implementation exhibits significant security concerns: use of curl | sh to install a binary (unverifiable binary risk), handling of private keys in a local config file (credential exposure risk), and potential network/data flow exposure through on-chain and API interactions. Overall, the footprint is suspicious to high-risk for credential handling and supply-chain risk, though the intended purpose (Polymarket interaction) is legitimate for a developer tooling scenario.

Confidence: 75%Severity: 78%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:45 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fclawdbot-skill-polymarket%2Fpolymarket%2F@b3856c156b316f8eace5c197add11381f916e7b3