grimoire-polymarket
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local commands through the
grimoireandpolymarketCLI tools. It includes built-in security constraints that explicitly block high-risk command groups such asshell,upgrade,wallet, andsetupto prevent unauthorized system modifications or sensitive wallet operations. - [EXTERNAL_DOWNLOADS]: The skill references external software for installation and execution, including the
@grimoirelabs/cliand@grimoirelabs/venuespackages from the NPM registry, and the officialpolymarketCLI via Homebrew. These downloads are associated with the primary functionality of the skill and use standard package management repositories. - [INDIRECT_PROMPT_INJECTION]: The skill processes external market data and user-supplied search parameters. Although it ingests data from external APIs, the risk is mitigated by the tool's design as a structured CLI wrapper that handles data primarily in JSON format, reducing the surface for prompt-based attacks. Evidence chain: (1) Ingestion points: market search queries and token IDs in SKILL.md. (2) Boundary markers: explicit command whitelist/blacklist in the wrapper. (3) Capability inventory: CLI execution and network requests in SKILL.md. (4) Sanitization: use of JSON formatting for agent data ingestion.
Audit Metadata