polymarket-mcp-server
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The capability set mostly matches a Polymarket trading skill, but the trust story is weak: the advertised publisher and install repo differ, installation uses a remote curl|bash script, and the skill asks the agent to handle a blockchain private key while enabling autonomous financial actions. That combination creates high security risk even without clear evidence of overt credential exfiltration.
Confidence: 88%Severity: 86%
Audit Metadata