polymarket-mcp-server

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The capability set mostly matches a Polymarket trading skill, but the trust story is weak: the advertised publisher and install repo differ, installation uses a remote curl|bash script, and the skill asks the agent to handle a blockchain private key while enabling autonomous financial actions. That combination creates high security risk even without clear evidence of overt credential exfiltration.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
May 18, 2026, 12:45 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fpolymarket-mcp-server%2F@0119142c40f564a5d9adccb99549e64a4d1addc8
Security Audit — socket — polymarket-mcp-server