Polymarket Btc 5m Mtf Momentum Dyll

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed BTC trading bot that can place live trades only when configured and run in live mode, but users should treat it as financially risky.

Install only if you intend to connect a Simmer trading account. Test in dry-run first, keep trade size small, use the narrowest API key permissions available, and understand that running with --live can place real trades and lose funds, especially if scheduled to run repeatedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill provides a direct 'Go live' command for trading without a clear, prominent warning that live mode can place real trades and cause financial loss or open real positions. In a trading context, this omission is more dangerous because users may treat the command as routine and enable live execution without understanding the monetary consequences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal