polymarket-ai-divergence

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities align with its stated purpose, but that purpose is inherently high risk: it lets an AI agent autonomously place real-money trades. The main concern is data-flow and execution trust: trade execution is routed through Simmer SDK/API endpoints rather than clearly documented direct official Polymarket endpoints, creating intermediary risk and unclear credential handling. No obvious malware or obfuscation is present, and there is no raw installer/download-execute chain in the provided skill text, but the combination of live financial action plus underspecified API/auth flows makes this a high-risk skill.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/spartanlabsxyz%2Fsimmer-sdk%2Fpolymarket-ai-divergence%2F@2f9f6872dc7f93f89a43a327f0570ba57d821b80