Back to skill

Security audit

LuckyLobster

Security checks across malware telemetry and agentic risk

Overview

This skill appears to support legitimate Polymarket trading, but it also enables high-impact automated and copy-trading actions that need clearer disclosure and user controls.

Review this carefully before installing. Only use it if you understand that the agent may place trades, approve tokens, close positions, redeem funds, or enable automated/copy-trading behavior using real money. Prefer using tight API permissions, small budgets, explicit confirmations, and disabling recurring or copy-trading features unless you intentionally want them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The manifest describes the skill only as trading/searching/managing positions, but the body also exposes autonomous strategies and copy-trading of third-party wallets. This materially understates the capability surface, which can mislead users and policy layers into authorizing a tool with far broader and more hazardous behavior than expected, including unattended financial actions.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Copy-trading another wallet expands the skill from direct user-directed market trading into surveillance-like monitoring of third-party activity followed by automatic execution. That broader capability increases financial, privacy, and misuse risk because an agent can mirror external actors in real time without a clear tie to the stated core purpose or strong user-consent boundaries.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill enables live order placement, position closing, token approvals, redemption, and autonomous strategies, yet it lacks a prominent warning that these actions can cause real financial loss and may be difficult or impossible to reverse once executed. In an agentic context, the absence of explicit risk disclosure makes accidental or over-broad delegation more dangerous because users may not appreciate that the agent can spend funds or trade automatically.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.