dapp-polymarket

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose mostly matches prediction-market research and trading, but the trust chain does not match the claimed OKX publisher: it installs an external CLI from a personal GitHub raw script, reruns that installer periodically, and then passes a Polygon private key into that tool for trading. Because an unverifiable third-party-installed CLI receives wallet credentials and can perform financial actions, this skill carries high security risk even though its user-facing functionality is coherent.

Confidence: 91%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fdapp-polymarket%2F@81946faac29e370754ccbb59665ccfc8d4330aab