Polymarket Trader

Security checks across malware telemetry and agentic risk

Overview

This skill is built for Polymarket trading, but it gives an agent live order-placement authority using a private key without enough confirmation or containment.

Review before installing. Use only a dedicated low-balance Polymarket key, verify market/side/price/size manually before each run, and avoid autonomous use until it adds explicit confirmation, dry-run support, strict value limits, and safer non-shell argument passing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This code performs a safety-critical, potentially irreversible operation by posting a market order to Polymarket. While it prints status messages, there is no confirmation prompt or explicit user warning immediately before the trade is submitted, so the user may not realize execution is final at runtime.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal