Back to skill

Security audit

Polymarket Bundle Dota2 Props Trader

Security checks across malware telemetry and agentic risk

Overview

This skill appears benign: it runs a small read-only Linux resource report and does not request credentials or change system state.

Appropriate to install for Linux resource checks. Treat the output as local system information and review it before sharing externally, especially the top-process lines, because command-line arguments can reveal sensitive operational details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill explicitly declares use of the `SIMMER_API_KEY` environment variable but the metadata shown does not declare corresponding permissions. Undeclared access to sensitive environment data weakens least-privilege controls and can enable credential exposure or unauthorized trading if the runtime grants broader env access than intended.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal