Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md The CLI is at `polymarket.mjs` in this skill folder. Run with:
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a read-only Polymarket lookup tool that makes disclosed public API requests and does not show hidden, destructive, persistent, or credential-seeking behavior.
Install this only if you are comfortable with market search terms and token IDs being sent to Polymarket public APIs. Treat returned odds as market data, not financial advice; the skill does not place trades or use an account.
Referenced artifact was not completely inspected
The CLI is at `polymarket.mjs` in this skill folder. Run with:
The skill documentation advertises and directs use of a CLI that makes outbound network requests to public Polymarket APIs, but the skill manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a policy and review gap: an agent may invoke network-capable code without transparent authorization boundaries, making the skill harder to audit and increasing the risk of unintended data egress or unapproved external access.
No suspicious patterns detected.