polymarket

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches prediction-market research and trading, but the execution path is an unverified intermediary backend that receives an OpenFinance API key, derives/caches Polymarket credentials server-side, and can perform financially consequential actions. No malware or installer evidence is present, but the credential routing, opaque backend trust, and autonomous trading capability make this a high security-risk skill.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:29 PM
Package URL
pkg:socket/skills-sh/openfinance-tech%2Fskills%2Fpolymarket%2F@151947d643f7ac7c30a58b58bc24f4c6c761160a