polymarket-plugin

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads its core binary, the onchainos CLI, and auxiliary scripts (launcher.sh, update-checker.py) from the okx organization's official GitHub repositories. These downloads are performed using verified SHA256 checksums to ensure integrity.
  • [REMOTE_CODE_EXECUTION]: The skill installs and executes remote scripts and binary tools at runtime. These components originate from the skill author's infrastructure and are essential for the skill's primary functionality of blockchain interaction and prediction market trading.
  • [COMMAND_EXECUTION]: The skill invokes the onchainos CLI and local executables to manage wallet sessions, sign EIP-712 messages, and execute smart contract calls on the Polygon network. All command invocations use a structured subprocess interface rather than an unsafe shell string.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests market questions and descriptions from external Polymarket APIs. It mitigates potential injection risks by instructing the agent to treat this data as untrusted and by using a sanitization module that strips control characters and truncates strings to 500 characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:52 PM