polymarket

Warn

Audited by Socket on Sep 17, 2026

4 alerts found:

Securityx2Anomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core trading capabilities fit the stated purpose and the scanner's command-injection hits are benign markdown, but the skill is still high risk because it enables autonomous real-money trading and transparently routes requests through an unverified internal proxy (sc-vpn.internal:8080) instead of only official Polymarket endpoints. Credential persistence in .env is also sensitive. This looks coherent as a trading skill, but its data flow and action profile make it unsafe to trust without strong review of the hidden proxy and explicit per-trade user approval.

Confidence: 90%Severity: 81%
SecurityMEDIUM
scripts/setup.py

The fragment appears intended as a Polymarket wallet setup script rather than malware. Its primary security concern is the deliberate granting of unlimited pUSD allowances and broad CTF operator permissions to hardcoded spenders; these should be independently verified before use. The shown file also contains a syntax error in the final print statements and will not execute as provided. Assessment is limited because imported helper modules are unavailable.

Confidence: 96%Severity: 72%
AnomalyLOW
scripts/common.py

No clear malware or intentional data theft is demonstrated in this fragment. The code appears to be an API client utility for Polymarket with VPN-based access handling. It presents meaningful security risks because sensitive credentials are stored in plaintext and authenticated traffic may be routed through the hardcoded sc-vpn.internal proxy. The proxy behavior and ownership should be independently verified before use, especially because the code automatically retries forbidden requests through alternate regions.

Confidence: 94%Severity: 58%
AnomalyLOW
_trade_report.py

The code implements opt-in-looking telemetry/reporting controlled by environment variables, but it sends trade events and CONTAINER_JWT to any configured endpoint without enforcing HTTPS or host allowlisting. This could enable data or credential disclosure if the environment is misconfigured or compromised. No clear malicious payload, hardcoded exfiltration destination, or other malware behavior is evident in this fragment.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fpolymarket%2F@29a3b7d9137afe0666560979871bec54932df0936f780ec0ccdbccfd93bd23f5
Security Audit — socket — polymarket