polymarket-profile
Pass
Audited by Gen Agent Trust Hub on Mar 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts exclusively with well-known public APIs associated with Polymarket (*.polymarket.com). These network operations are standard for the tool's stated purpose of address profiling and do not involve sensitive data.
- [SAFE]: No sensitive data exposure or exfiltration patterns were identified. The skill does not access local configuration files (~/.ssh, ~/.aws, .env), environment variables, or hardcoded credentials.
- [SAFE]: Command execution is limited to curl requests for data retrieval. There is no evidence of piping remote content to shells or any other form of remote code execution (RCE).
- [SAFE]: No obfuscation techniques, persistence mechanisms, or privilege escalation attempts were found in the skill's instructions or metadata.
- [SAFE]: Although the skill processes external data (market titles and usernames), it lacks the exploitable capability chains required for a meaningful indirect prompt injection finding.
Audit Metadata