polymarket

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core trading capability matches the stated purpose, but the skill has a disproportionate trust footprint. It installs multiple external components, transitively installs other skills, downloads a standalone binary, sends install telemetry to a Vercel endpoint, and enables autonomous high-impact financial actions plus forced approvals. This looks more like a risky wallet/trading plugin ecosystem than clear malware, but it should be treated as high-risk.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Apr 13, 2026, 02:30 AM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fpolymarket%2F@0716f729dde6292d32c4576bca046faefe39f308