polymarket-plugin

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Polymarket trading, but its footprint is high-risk for an AI agent because it combines real-money actions with remote installers, binary downloads, local credential caching, and transitive skill installation. The main concern is execution trust and autonomous financial capability, not clear evidence of malware or credential theft.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:10 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fpolymarket-plugin%2F@c9214ba7f488db4bcde96f904056c65752ce74d5