polymarket-copytrading

Warn

Audited by Snyk on Feb 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to execute real trades on a financial/crypto prediction market. It uses the Simmer API/SDK to fetch portfolios and positions and to "execute trades" (steps describe calculating rebalance trades and executing them), provides CLI flags to "Execute real trades" (--live), "full rebalance" (buys AND sells), and "sell when whales exit". It also documents using a WALLET_PRIVATE_KEY env var so the SDK can sign orders. These are direct market-order / wallet-signing capabilities (crypto wallet management and order execution), not generic tooling. Therefore it grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 12:36 PM