Back to skill

Security audit

Polymarket Macro Risk Regime Trader

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Polymarket trading skill that defaults to paper trading and only makes live trades when explicitly run with the live flag.

Install only if you intend to connect a Simmer/Polymarket trading workflow. Start in paper mode, use a scoped and rotateable SIMMER_API_KEY, review the position limits, and use --live only when you accept real USDC trading risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The manifest declares a required API credential (`SIMMER_API_KEY`) but gives the user no explanation of what the key is used for, where it is sent, or what actions it authorizes. In an automated trading skill, undisclosed credential use increases the risk of users supplying sensitive secrets without understanding scope, and it impairs informed consent and security review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal