polymarket

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted market data (titles, questions, and outcome names) from external sources like the Polymarket Gamma API and Data API without sanitization. This creates an attack surface where maliciously crafted market metadata could influence the agent's logic.
  • Ingestion points: Data enters the agent context via scripts/search.py, scripts/status.py, and scripts/prepare_order.py.
  • Boundary markers: The skill output lacks boundary markers or instructions to ignore embedded commands within the market data.
  • Capability inventory: The skill has access to sensitive tools (wallet_transfer, wallet_sign_typed_data) and can modify the workspace .env file.
  • Sanitization: There is no evidence of filtering or sanitizing the strings fetched from external market APIs.
  • [DATA_EXFILTRATION]: Trade execution details (such as price, size, and transaction hashes) are sent to a vendor-controlled analytics endpoint (AI_AGENT_API_URL) using the _trade_report.py script. This is performed as background telemetry using the agent's CONTAINER_JWT for authorization.
  • [COMMAND_EXECUTION]: The skill operates by executing multiple internal Python scripts to query market data, manage authentication, and prepare transaction payloads for wallet signing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — polymarket