Back to skill

Security audit

Mia Polymarket Trader

Security checks across malware telemetry and agentic risk

Overview

This skill openly describes an automated Polymarket trader, but it asks for wallet-level credentials and live trading authority without enough scoping, safety controls, or implementation provenance.

Review carefully before installing. Use only a dedicated low-balance wallet, verify the actual mia-polymarket command from a trusted source, and require dry-run mode or manual confirmation before any live trade. Do not provide a primary wallet private key unless the publisher supplies reviewed code, enforceable limits, and clear credential-handling documentation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes autonomous market analysis and automated trade execution on a real-money prediction market, but it does not warn users about irreversible financial loss, market volatility, execution errors, or regulatory/account risks. In a trading context, omission of these warnings is dangerous because users may enable automation without understanding that the agent can place real trades with immediate monetary consequences.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The setup instructions tell users to export a Polymarket API key and a wallet private key directly into the shell environment without any warning about secret handling, wallet compromise, or the consequences of exposing a signing key. In this context, the private key can authorize real asset movements or trading actions, so weak guidance around credential handling materially increases the risk of account takeover or irreversible financial loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.