Back to skill

Security audit

Polymarket Preflight (TickTape)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only Polymarket risk-check helper that calls a paid external API but does not install code, take custody, or execute trades.

Before installing, understand that live use can spend real USDC through x402 or prepaid credits and may influence trading decisions. Use sandbox/probe mode first, enforce local spend caps, verify the payment recipient, and keep any tk_ credit token secret.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.