Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Poly Master
v1.0.0Polymarket prediction market skill by Antalpha AI. Discover trending markets, browse event predictions, invest in outcomes, copy-trade top traders, track por...
⭐ 0· 36·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Benign
medium confidencePurpose & Capability
Name/description match the documented behavior: the skill routes Polymarket discovery, trading, copy-trading, and portfolio features through the Antalpha MCP server. No unrelated binaries or credentials are requested and the listed MCP tools align with the described capabilities.
Instruction Scope
SKILL.md stays within the stated domain (market discovery, trading, copy-trading, signing flows). It explicitly instructs the agent to register with antalpha-register and persist agent_id + api_key. It does not direct the agent to read unrelated system files or environment variables, but it does require the agent to generate/persist credentials at runtime — storage location and handling are unspecified.
Install Mechanism
Instruction-only skill with no install spec and no code files: lowest install risk. Nothing is downloaded or written to disk by an installer step in the package itself.
Credentials
The package declares no required env vars, which is fine; however the runtime flow requires registering to obtain an agent_id and api_key and explicitly tells the agent to persist them. Those are sensitive credentials created at runtime but are not described in terms of where/how they will be stored or what privileges the api_key grants on the MCP server.
Persistence & Privilege
The skill does not set always:true and uses normal autonomous invocation defaults. The only persistent action described is storing the agent_id/api_key produced by registration. There is no instruction to modify other skills or system-wide settings.
Assessment
This skill appears coherent for its stated purpose, but before installing: (1) verify the MCP endpoint (https://mcp-skills.ai.antalpha.com) and the publisher (Antalpha AI) are legitimate and trustworthy; (2) ask where your agent will store the agent_id/api_key (skill requests you "persist both values") and ensure they are stored securely (not in plain-text logs or public skill metadata); (3) always open signing links in your wallet's trusted browser and never paste private keys — the skill uses EIP-712 signatures, but signing authorizes on-chain orders; (4) start with minimal funds when testing copy-trading or automated mirroring to limit financial risk; and (5) confirm local regulatory compliance for prediction market activity.Like a lobster shell, security has layers — review code before you run it.
latestvk9730965ef3cb58hqfz7bcehy584nr73
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🎯 Clawdis
