Polymarketskill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Polymarket market-data helper with local watchlists and simulated paper trading, and I found no evidence of real trading, credential use, or hidden behavior.

Install only if you are comfortable with the skill contacting Polymarket's public API and storing watchlist and simulated portfolio data in ~/.polymarket/. Add the cron examples only if you want recurring checks; this skill does not perform real trades or use wallet credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill documentation describes capabilities to make network requests to a public API and to read/write local JSON files under ~/.polymarket/, but the manifest declares no explicit permissions. This creates a permission-transparency issue: users and policy engines may not be able to accurately assess or enforce what the skill can access, even though the described behavior appears aligned with the skill's stated purpose and not overtly malicious.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal