storyclaw-polymarket-trading

Warn

Audited by Socket on Mar 18, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses official Polymarket tooling, so it does not look like credential harvesting malware. However, it grants an AI agent high-impact financial autonomy, stores raw wallet private keys locally, and establishes persistent cron-based execution, making the overall security risk high even though malicious intent is not evident.

Confidence: 90%Severity: 84%
AnomalyLOW
credentials/example.json

This JSON is a credentials/configuration file that contains placeholders for sensitive secrets (private key and API credentials). The file itself is not executable or directly malicious, but storing real secrets here in plaintext is a significant supply-chain and operational security risk: if these values are populated and the file is committed, leaked, or read by an attacker, they enable account compromise and theft. Treat this file as high-sensitivity material; do not commit to source control, use secret management, and rotate keys if they were exposed.

Confidence: 90%Severity: 65%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/storyclaw-official%2Ftalenthub%2Fstoryclaw-polymarket-trading%2F@59f0895d6009150e90040d02d2ead080125d358e