polymarket-live-executor
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
scripts/setup_wallet.pyutility outputs the generated burner wallet private key directly to the terminal in plain text during the creation process. While necessary for initial user setup, this poses a risk of capture by local logging or terminal history.- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external market data which could theoretically contain malicious prompt instructions.- Ingestion points:
scripts/execute_live.pyfetches order book context;scripts/check_positions.pyfetches active orders and trade history. - Boundary markers: Mandatory interactive confirmation (requiring a literal 'yes' input) and the
POLYMARKET_CONFIRMenvironment safety gate. - Capability inventory: Ability to sign and submit blockchain transactions via
client.post_order. - Sanitization: External API responses are parsed as structured JSON and formatted for display.- [COMMAND_EXECUTION]: The skill provides scripts that execute authenticated blockchain transactions and manage financial assets, though these are gated by manual triggers and environment configurations.
- Ingestion points:
Audit Metadata