polymarket-live-executor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The scripts/setup_wallet.py utility outputs the generated burner wallet private key directly to the terminal in plain text during the creation process. While necessary for initial user setup, this poses a risk of capture by local logging or terminal history.- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external market data which could theoretically contain malicious prompt instructions.
    • Ingestion points: scripts/execute_live.py fetches order book context; scripts/check_positions.py fetches active orders and trade history.
    • Boundary markers: Mandatory interactive confirmation (requiring a literal 'yes' input) and the POLYMARKET_CONFIRM environment safety gate.
    • Capability inventory: Ability to sign and submit blockchain transactions via client.post_order.
    • Sanitization: External API responses are parsed as structured JSON and formatted for display.- [COMMAND_EXECUTION]: The skill provides scripts that execute authenticated blockchain transactions and manage financial assets, though these are gated by manual triggers and environment configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:37 PM
Security Audit — agent-trust-hub — polymarket-live-executor