Polymarket News Events

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed automated trading skill, but live mode can place real trades automatically from RSS-based heuristics with limited built-in exposure controls.

Install only if you intend to run financial automation. Start in dry-run or simulation, use a least-privileged trading key, keep trade size low, and do not enable live scheduled runs unless you have independent account limits and monitoring.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises and relies on capabilities including environment variable access, network access, and local file read/write, but the manifest does not declare any permissions. This creates a transparency and policy-enforcement gap: reviewers and runtime controls may underestimate what the skill can do, which is especially concerning for an automated trading skill that consumes external news feeds and can act on API credentials.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
When run with --live, the skill submits trades immediately based on noisy external RSS inputs and heuristic matching, without any final confirmation, kill switch, or explicit user acknowledgment at the moment of execution. In an automated trading skill, this increases the chance of unintended or erroneous real-money actions from false matches, manipulated feed content, or operator mistake.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal