@1368/polymarket-trade

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for Polymarket trading and uses official Polymarket APIs and contract addresses, but it enables real-money financial actions, stores raw trading credentials, and routes sensitive CLOB traffic through an unverifiable internal proxy. The biggest risk is data-flow integrity and autonomous financial impact rather than classic malware or installer abuse.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fcommunity-skills%2Fpolymarket-trade%2F@3abe273e85156f4fcf58b5da05c328f817d88c5e