扫描报告
5 /100
Polymarket-Brain
Automated geopolitical and macroeconomic analysis pipeline that fetches CNBC news, routes to expert skills, matches Polymarket prediction markets, and delivers trading recommendations to Discord
A legitimate market-analysis pipeline that fetches news, routes to expert skills, matches Polymarket markets, and posts to Discord. No malicious indicators found—no credential theft, exfiltration, obfuscation, or undeclared sensitive behavior.
可以安装
Approve for use. Consider pinning Discord webhook URLs in environment variables rather than hardcoding across scripts.
安全发现 3 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | subprocess usage not explicitly declared in SKILL.md 文档欺骗 | polymarket_brain_orchestrator.py:68 |
| 低危 | Hardcoded Windows user path in multiple scripts 文档欺骗 | run_workflow.py:11 |
| 低危 | Discord webhook tokens hardcoded in source files 敏感访问 | send_discord.py:9 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 网络访问 | READ | READ | ✓ 一致 | urllib/requests to CNBC RSS, Polymarket API, Discord webhooks—all documented and… |
| 文件系统 | WRITE | WRITE | ✓ 一致 | Writes output JSON, analysis files, logs to output/ and memory/ directories |
| 命令执行 | WRITE | WRITE | ✓ 一致 | subprocess.run([sys.executable, script]) for local Python scripts—documented and… |
| 环境变量 | NONE | READ | ✓ 一致 | Reads USERPROFILE, APPDATA, SKILLS_ROOT, PYTHONIOENCODING—standard env vars for … |
| 技能调用 | READ | READ | ✓ 一致 | Routes to geopolitics-expert, the-fed-agent via keyword classification |
| 剪贴板 | NONE | NONE | — | Not used |
| 浏览器 | NONE | NONE | — | Not used; references to browser skills are routing logic, not actual browser inv… |
| 数据库 | NONE | NONE | — | Not used |
62 项发现
中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1483478506070474922/ReIZsU3KTpXqNseTWFBNsuPJ-FbYgqEuCTELtMHRWw4ND8vVjMUr36b6LyusiOoJn66... FINAL_SUMMARY.txt:82 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1483478506070474922/... INSTALLATION_COMPLETE.txt:101 中危 外部 URL 外部 URL
https://polymarket.com/event/will-the-iranian-regime-fall-by-june-30 KNOWLEDGE_SNAPSHOT.json:41 中危 外部 URL 外部 URL
https://polymarket.com/event/us-x-iran-ceasefire-by KNOWLEDGE_SNAPSHOT.json:46 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-x-israelus-conflict-ends-by KNOWLEDGE_SNAPSHOT.json:51 中危 外部 URL 外部 URL
https://polymarket.com/event/us-forces-enter-iran-by KNOWLEDGE_SNAPSHOT.json:56 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-leadership-change-by KNOWLEDGE_SNAPSHOT.json:61 中危 外部 URL 外部 URL
https://polymarket.com/event/fed-decision-in-march KNOWLEDGE_SNAPSHOT.json:66 中危 外部 URL 外部 URL
https://polymarket.com/event/will-crude-oil-cl-hit-by-end-of-march KNOWLEDGE_SNAPSHOT.json:71 中危 外部 URL 外部 URL
https://polymarket.com/event/us-recession-by-end-of-2026 KNOWLEDGE_SNAPSHOT.json:76 中危 外部 URL 外部 URL
https://www.cnbc.com/world-politics/ PERSISTENCE_VERIFICATION.md:36 中危 外部 URL 外部 URL
https://polymarket.com/ PERSISTENCE_VERIFICATION.md:37 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1482043765471445333/YOUR_KEY_HERE README.md:84 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1482043765471445333/YOUR_KEY README.md:89 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1483478506070474922/YOUR_KEY README.md:90 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1482043765471445333/... SKILL.md:32 中危 外部 URL 外部 URL
https://polymarket.com/event/will-crude-oil-cl-hit__-by-end-of-march SKILL.md:252 中危 外部 URL 外部 URL
https://polymarket.com/event/will-crude-oil-cl-hit-100-by-end-of-march SKILL.md:253 中危 外部 URL 外部 URL
https://discord.com/... TROUBLESHOOTING.md:169 中危 外部 URL 外部 URL
https://polymarket.com/event/ ai_analyzer.py:401 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/iran-war-uae-energy-gas-field-oil-fujairah-strait-of-hormuz.html analysis/geopolitics-expert-2026-03-17.md:5 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/treasury-yields-middle-east-tensions-fed-decision.html analysis/the-fed-agent-2026-03-17.md:5 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/18/trump-jones-act-oil-iran-war.html output/analysis_input_1.json:4 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/18/vance-oil-industry-gas-prices-iran-war.html output/analysis_input_2.json:4 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/18/dot-plot-fed-still-expects-to-cut-rates-once-this-year-despite-spiking-oil-prices-.html output/analysis_input_5.json:4 中危 外部 URL 外部 URL
https://polymarket.com/event/will-the-iranian-regime-fall-by-the-end-of-2026 output/discord-message.md:35 中危 外部 URL 外部 URL
https://polymarket.com/event/us-iran-nuclear-deal-before-2027 output/discord-message.md:36 中危 外部 URL 外部 URL
https://polymarket.com/event/will-the-us-invade-iran-before-2027 output/discord-message.md:37 中危 外部 URL 外部 URL
https://polymarket.com/event/russia-x-ukraine-ceasefire-before-2027 output/discord-message.md:38 中危 外部 URL 外部 URL
https://polymarket.com/event/oil-exceeds-120-before-june-2026 output/discord-message.md:39 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/18/european-markets-stoxx-600-ftse-dax-cac-iran-news-oil-prices.html output/phase2_analyses.json:91 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/18/ai-data-center-buildout-jobs-salary-skilled-traders-worker-shortage.html output/phase2_analyses.json:124 中危 外部 URL 外部 URL
https://polymarket.com/event/will-iranian-regime-fall-by-june-30? output/phase3_markets.json:12 中危 外部 URL 外部 URL
https://polymarket.com/event/us-x-iran-ceasefire-by-december-31? output/phase3_markets.json:22 中危 外部 URL 外部 URL
https://polymarket.com/event/us-forces-enter-iran-by-december-31? output/phase3_markets.json:32 中危 外部 URL 外部 URL
https://polymarket.com/event/will-crude-oil-hit-$100+-by-end-of-march? output/phase3_markets.json:42 中危 外部 URL 外部 URL
https://polymarket.com/event/us-recession-by-end-of-2026? output/phase3_markets.json:52 中危 外部 URL 外部 URL
https://polymarket.com/event/will-crude-oil-cl-hit-120-by-june-30 output/polymarket-brain-summary-2026-03-17.md:60 中危 外部 URL 外部 URL
https://discord.com/api/webhooks/1482043765471445333/-cHOLCqBtvU_Wua8STfoINes7J0pFNFsXB27EJ3f8F7BklC5P_OkIGAx2HQLDPZe1bN... polymarket_brain_orchestrator.py:30 中危 外部 URL 外部 URL
https://www.cnbc.com/iran-gulf polymarket_brain_orchestrator.py:356 中危 外部 URL 外部 URL
https://www.cnbc.com/oil-hormuz polymarket_brain_orchestrator.py:357 中危 外部 URL 外部 URL
https://www.cnbc.com/fed-stagflation polymarket_brain_orchestrator.py:358 中危 外部 URL 外部 URL
https://gamma-api.polymarket.com/events references/config.md:7 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-x-us-israel-conflict-ends-by-2026 references/discord-format.md:43 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-leadership-change-2026 references/discord-format.md:45 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/epstein-pam-bondi-trump-doj-subpoena.html scripts/cnbc_articles_output.md:7 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/trump-nato-iran-war-allies-china.html scripts/cnbc_articles_output.md:24 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/save-america-act-voter-id-trump-senate.html scripts/cnbc_articles_output.md:40 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/dhs-shutdown-trump-homeland-security-senate-democrats-counteroffer.html scripts/cnbc_articles_output.md:56 中危 外部 URL 外部 URL
https://www.cnbc.com/2026/03/17/this-tech-stock-is-primed-for-a-big-move-higher-how-to-trade-it-using-options.html scripts/cnbc_articles_output.md:73 中危 外部 URL 外部 URL
https://polymarket.com/api scripts/orchestrate.py:29 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-regime-fall scripts/orchestrate.py:152 中危 外部 URL 外部 URL
https://polymarket.com/event/us-iran-ceasefire scripts/orchestrate.py:158 中危 外部 URL 外部 URL
https://polymarket.com/event/fed-rate-cut scripts/orchestrate.py:166 中危 外部 URL 外部 URL
https://www\.cnbc\.com/[^\s scripts/run_polymarket_brain.py:163 中危 外部 URL 外部 URL
https://polymarket.com/event/iran-conflict-ends-2026 scripts/send_discord_summary.py:113 中危 外部 URL 外部 URL
https://polymarket.com/market/fed scripts/send_markets.py:20 中危 外部 URL 外部 URL
https://polymarket.com/market/inflation scripts/send_markets.py:21 中危 外部 URL 外部 URL
https://polymarket.com/market/treasury scripts/send_markets.py:22 中危 外部 URL 外部 URL
https://polymarket.com/market/stagflation scripts/send_markets.py:23 中危 外部 URL 外部 URL
https://polymarket.com/market/oil scripts/send_markets.py:24 中危 外部 URL 外部 URL
https://polymarket.com/event/will-the-iranian-regime-fall-by-june-30\n test_message_length.py:39 目录结构
52 文件 · 242.7 KB · 6484 行 Python 21f · 3479L
Markdown 17f · 2236L
JSON 11f · 427L
Text 3f · 342L
├─
▾
analysis
│ ├─
geopolitics-expert-2026-03-17.md
Markdown
│ └─
the-fed-agent-2026-03-17.md
Markdown
├─
▾
memory
│ ├─
2026-03-17-cnbc-fed-treasurys.md
Markdown
│ └─
2026-03-17-cnbc-iran-uae.md
Markdown
├─
▾
output
│ ├─
analysis_input_1.json
JSON
│ ├─
analysis_input_2.json
JSON
│ ├─
analysis_input_3.json
JSON
│ ├─
analysis_input_4.json
JSON
│ ├─
analysis_input_5.json
JSON
│ ├─
discord-message.md
Markdown
│ ├─
discord-payload.json
JSON
│ ├─
phase1_articles.json
JSON
│ ├─
phase2_analyses.json
JSON
│ ├─
phase2_expert_analysis.json
JSON
│ ├─
phase3_markets.json
JSON
│ └─
polymarket-brain-summary-2026-03-17.md
Markdown
├─
▾
references
│ ├─
config.md
Markdown
│ ├─
discord-format.md
Markdown
│ └─
workflow.md
Markdown
├─
▾
scripts
│ ├─
cnbc_articles_output.md
Markdown
│ ├─
orchestrate.py
Python
│ ├─
orchestrator.py
Python
│ ├─
run_full_workflow.py
Python
│ ├─
run_polymarket_brain.py
Python
│ ├─
run_workflow.py
Python
│ ├─
send_discord_summary.py
Python
│ ├─
send_discord.py
Python
│ └─
send_markets.py
Python
├─
ai_analyzer.py
Python
├─
FINAL_SUMMARY.txt
Text
├─
GUARANTEE.txt
Text
├─
INSTALLATION_COMPLETE.txt
Text
├─
KNOWLEDGE_SNAPSHOT.json
JSON
├─
PERSISTENCE_VERIFICATION.md
Markdown
├─
polymarket_brain_orchestrator_FIXED.py
Python
├─
polymarket_brain_orchestrator.py
Python
├─
PRE_TEST_CHECKLIST.md
Markdown
├─
README.md
Markdown
├─
RESTART_GUARANTEE.md
Markdown
├─
run_phases_2_4.py
Python
├─
send_discord.py
Python
├─
send_to_discord.py
Python
├─
SKILL.md
Markdown
├─
test_both_webhooks.py
Python
├─
test_message_length.py
Python
├─
test_orchestrator_header.py
Python
├─
test_phase1_webhook.py
Python
├─
test_urllib_headers.py
Python
├─
test_urllib.py
Python
├─
test_webhook.py
Python
├─
TROUBLESHOOTING.md
Markdown
└─
WORKFLOW_LOGIC.md
Markdown
安全亮点
✓ No credential harvesting—skill never accesses ~/.ssh, ~/.aws, .env, or similar sensitive paths
✓ No data exfiltration—outbound network requests only to legitimate APIs (CNBC RSS, Polymarket API, Discord webhooks)
✓ No obfuscation—zero base64, atob, eval(), or hidden encoded payloads
✓ No remote script execution—subprocess only invokes local Python scripts within the skill bundle
✓ Documentation is accurate—SKILL.md accurately describes the 4-phase workflow and matches code behavior
✓ No supply chain threats—uses standard libraries (requests, urllib, json, subprocess) with no external dependencies declared
✓ Skill self-contains its outputs—analysis results written to local output/ directory, not exfiltrated
✓ Exit code 0 always on no-new-news is a good resilience pattern
✓ No persistence mechanisms—no cron, startup hooks, or backdoor installation detected
✓ Discord webhook tokens are public Discord webhooks (not server-side secrets) but still should be env-variable backed