grimoire-polymarket

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands through the grimoire and polymarket CLI tools. It includes built-in security constraints that explicitly block high-risk command groups such as shell, upgrade, wallet, and setup to prevent unauthorized system modifications or sensitive wallet operations.
  • [EXTERNAL_DOWNLOADS]: The skill references external software for installation and execution, including the @grimoirelabs/cli and @grimoirelabs/venues packages from the NPM registry, and the official polymarket CLI via Homebrew. These downloads are associated with the primary functionality of the skill and use standard package management repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external market data and user-supplied search parameters. Although it ingests data from external APIs, the risk is mitigated by the tool's design as a structured CLI wrapper that handles data primarily in JSON format, reducing the surface for prompt-based attacks. Evidence chain: (1) Ingestion points: market search queries and token IDs in SKILL.md. (2) Boundary markers: explicit command whitelist/blacklist in the wrapper. (3) Capability inventory: CLI execution and network requests in SKILL.md. (4) Sanitization: use of JSON formatting for agent data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:17 AM
Security Audit — agent-trust-hub — grimoire-polymarket