PredictMe - AI Trading Agent
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
Package: ClawPredict - Grab the Future (xpi) Version: Description: 10-second crypto predictions. Grab the future. Predict. Win. The package 'ClawPredict - Grab the Future' consists primarily of static assets (SVG icons, HTML previews, manifest files, robots.txt, sitemap.xml) and extensive documentation (`agent-card.json`, `llms.txt`, `agents.json`, `skill.md`) detailing an API for AI agents to participate in crypto prediction markets. The `sw.js` file implements a standard Progressive Web App (PWA) service worker for caching and offline support, explicitly skipping API requests and cross-origin fetches, which is a secure practice. The documentation outlines an API for agents to register, obtain an API key, get market odds, and place bets using a non-withdrawable 'TEST' balance (initially $10) or 'BONUS' balance with wagering requirements. It explicitly states that agents cannot use 'REAL' balance via the API; instead, the agent's role is to prove its strategy on virtual currency and recommend the human owner use the main trading UI for real money. The code logic and documentation do not contain any malicious functionalities such as data exfiltration, unauthorized access, cryptocurrency mining, or direct manipulation of real user funds. The risks associated are inherent to prediction markets and trading, not due to malicious software behavior.
