Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The script can place live market orders via 'polymarket clob market-order' when --execute is supplied, which goes beyond passive analysis or workflow-building and turns the skill into a trading executor. In the context of an agent skill, this is dangerous because user-provided or loosely reviewed configuration can trigger irreversible financial actions, increasing the risk of unauthorized trades, loss of funds, and misuse of connected credentials.
