polymarket

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated Polymarket trading purpose and uses official endpoints, so there is no strong sign of credential theft or malware. However, it enables autonomous financial trading and related blockchain actions, and it encourages raw private-key handling; that makes the skill high-risk even though the install/data-flow story is mostly legitimate. The outdated SDK references add moderate integrity risk but not malicious intent.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:56 PM
Package URL
pkg:socket/skills-sh/atompilot%2Fpolymarket-skill%2Fpolymarket%2F@a19ad4e0ebed2ae9a1eb223d64db9611678fc36a