polyclaw

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and mainly uses legitimate services, but it grants an AI agent direct financial trading power, requires a raw private key, and may route exchange traffic through third-party proxies. This is not confirmed malware, but it is a high-risk trading skill with meaningful secret-handling and real-world action exposure.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:32 PM
Package URL
pkg:socket/skills-sh/chainstacklabs%2Fpolyclaw%2Fpolyclaw%2F@1f5a8ab02b9fd5aa2bbb5b88e5bca8b8947655d1