Better Polymarket Security Audit Report
Better Polymarket is an AI agent skill, created by wz14 and published at wz14/better_polymarket. ClawSecure audited Better Polymarket across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 30/100 (High Risk). The 12 findings concentrate in Data Exfiltration, Command Injection and Code Injection, including Pipeline downloads data from the network and executes it:β¦ and OS Command Execution. 4 were rated high or critical severity.
Is Better Polymarket safe?
ClawSecure audited Better Polymarket and assigned a security score of 30/100 (High Risk), identifying 12 findings across Data Exfiltration and Command Injection. Review the findings below before installing.
What did ClawSecure find in Better Polymarket?
ClawSecure identified 12 findings in Better Polymarket, concentrated in Data Exfiltration, Command Injection and Code Injection. 4 were rated high or critical severity. The most severe include Pipeline downloads data from the network and executes it:β¦ and OS Command Execution.
How was Better Polymarket audited?
ClawSecure ran Better Polymarket through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from wz14/better_polymarket.
What does a score of 30 mean?
ClawSecure assigned Better Polymarket a security score of 30/100, placing it in the High Risk range. This is driven by 12 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for Better Polymarket
ClawSecure detected 12 security findings in Better Polymarket, spanning Data Exfiltration, Command Injection, Code Injection and Policy Violation.
- high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scripts/polymarket.py:1. - high · OS Command Execution. Command Injection finding detected in
scripts/polymarket.py:179. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
polymarket.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
polymarket.py. - medium · Undeclared Network Access. Unauthorized Tool Use finding detected in
SKILL.md. - medium · Outbound HTTP Request Detected. Data Exfiltration finding detected in
scripts/polymarket.py:24. - medium · Outbound HTTP Request Detected. Data Exfiltration finding detected in
scripts/polymarket.py:180. - medium · Outbound HTTP Request Detected. Data Exfiltration finding detected in
scripts/polymarket.py:217. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- medium · ReDoS vulnerability: Nested quantifiers (potentialβ¦. ReDoS finding detected in
polymarket.py:378. - info · Skill name 'Better Polymarket' is invalid. Agent skillsβ¦. Policy Violation finding detected in
SKILL.md. - info · Missing License Declaration. Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for Better Polymarket
Audit external network connections
Harden command execution
Eliminate dynamic code execution
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI AgentsβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβRelated AI Agent Security Audits
Scanned on July 6, 2026. Better Polymarket is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.