Back to skill

Security audit

Polymarket Worldcup Copytrader

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed automated trading skill that can place real Polymarket orders only when the user enables live mode, with clear limits and warnings.

Install only if you are comfortable with automated trading risk. Keep the default dry-run and sim venue until you have reviewed the planned trades, set conservative WC_COPYTRADER_MAX_USD and WC_COPYTRADER_MAX_TRADES values, and use --venue polymarket --live only when you intend to place real USDC orders with the configured wallet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_copytrader.py:144