Poly Tradebot

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed public-news and Polymarket research workflow, but its trading-style YES/NO outputs should be treated as informational and manually verified.

Install only if you want a research aid for public news and prediction-market analysis. Do not treat its YES/NO table as financial advice or an instruction to trade; verify market odds, volume, dates, resolution rules, and the underlying news yourself, and clear old memory files if stale analyses should not influence later results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This file presents direct affirmative trading recommendations such as '**YES**' and '**NO**' tied to real-world prediction markets without any risk disclaimer, uncertainty framing, or warning that the content is not financial advice. In the context of an automated news-to-trading-signal skill, this is more dangerous because users may reasonably treat the output as actionable investment guidance and rely on probabilistic or potentially stale analysis to place trades.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal