Back to skill

Security audit

Alphagbm Polymarket

Security checks for vulnerabilities and agentic risk

Overview

This skill is a non-executable financial-analysis prompt guide with some investment-risk disclosure gaps but no hidden code, persistence, credential use, or destructive behavior.

Before installing, understand that this skill can surface actionable-sounding options trade ideas from probability comparisons. Treat outputs as research prompts only, verify any data source and assumptions independently, and do not rely on it as financial advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains broad phrases such as 'event probability', 'rate cut odds', and 'prediction market data' that can plausibly appear in normal financial conversations, increasing the chance of unintended skill activation. In a trading-oriented skill, accidental invocation can surface misleading or action-oriented outputs in the wrong context, creating prompt-routing and user-safety risks.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promises 'suggested options trades to exploit the mispricing' without any accompanying risk disclosure, suitability warning, or indication that outputs are informational rather than financial advice. Because the content is event-driven and framed as actionable arbitrage, users may over-trust the outputs and make high-risk trading decisions based on incomplete or mock-data-derived analysis.

Static analysis

No suspicious patterns detected.