Atlas / MCP servers / caiovicentino / Polymarket

PolymarketCAUTION

mcp/caiovicentino/polymarket-6

🤖 AI-Powered MCP Server for Polymarket - Enable Claude to trade prediction markets with 45 tools, real-time monitoring, and enterprise-grade safety features

Verdict
CAUTION
Grade
C
Trust score
71 /100
Exposed tools
24 20r · 4w · 0d
Transport
stdio
License
MIT
Stars
679
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/downloads/) [](LICENSE) [](https://modelcontextprotocol.io) [](#testing) [](https://agentseal.org/mcp/polymarket-mcp)

Complete AI-Powered Trading Platform for Polymarket Prediction Markets

Enable Claude to autonomously trade, analyze, and manage positions on Polymarket with 45 comprehensive tools, real-time WebSocket monitoring, and enterprise-grade safety features.

👨💻 Created By

[Caio Vicentino](https://github.com/caiovicentino)

Developed in collaboration with:

  • 🌾 [Yield Hacker](https://opensea.io/collection/yield-hacker-pass-yhp) - DeFi Innovation Community
  • 💰 [Renda Cripto](https://rendacripto.com.br/) - Crypto Trading Community
  • 🏗️ [Cultura Builder](https://culturabuilder.com/) - Builder Culture Community

Powered by [Claude Code](https://claude.ai/code) from Anthropic

⭐ Key Features

🎯 45 Comprehensive Tools Across 5 Categories

🔍Market Discovery8 tools 📊Market Analysis10 tools 💼Trading12 tools 📈Portfolio8 tools ⚡Real-time7 tools

🔍 Market Discovery (8 tools)

  • Search and filter markets by keywords, categories, events
  • Trending markets by volume (24h, 7d, 30d)
  • Category-specific markets (Politics, Sports, Crypto)
  • Markets closing soon alerts
  • Featured and promoted markets
  • Sports markets (NBA, NFL, etc.)
  • Crypto prediction marke
Read from source at commit e670de3259e8OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add polymarket-mcp --env POLYGON_PRIVATE_KEY=${POLYGON_PRIVATE_KEY} --env POLYMARKET_API_KEY=${POLYMARKET_API_KEY} --env POLYMARKET_PASSPHRASE=${POLYMARKET_PASSPHRASE} -- uvx polymarket-mcp
claude-desktop
{
  "mcpServers": {
    "polymarket-mcp": {
      "command": "uvx",
      "args": [
        "polymarket-mcp"
      ],
      "env": {
        "POLYGON_PRIVATE_KEY": "${POLYGON_PRIVATE_KEY}",
        "POLYMARKET_API_KEY": "${POLYMARKET_API_KEY}",
        "POLYMARKET_PASSPHRASE": "${POLYMARKET_PASSPHRASE}"
      }
    }
  }
}
03

Exposed tools (24)

20 read · 4 write · 0 destructive.

ToolRiskDescription
analyze_market_opportunityreadAI-powered market analysis with trading recommendation, risk assessment, and confidence score.
cancel_all_ordersreadCancel all open orders across all markets. Use with caution.
cancel_market_ordersreadCancel all open orders in a specific market.
cancel_orderwriteCancel a specific open order by ID.
compare_marketsreadCompare multiple markets side-by-side with key metrics (volume, liquidity, etc.).
filter_markets_by_categoryreadFilter markets by category or tag (e.g., Politics, Sports, Crypto). Returns markets in the specified category.
get_closing_soon_marketsreadGet markets closing within specified timeframe. Returns markets sorted by closing time.
get_crypto_marketsreadGet cryptocurrency-related markets. Optionally filter by specific crypto symbol.
get_current_pricereadGet current bid/ask prices for a token. Returns PriceData with bid, ask, and mid prices.
get_event_marketsreadGet all markets for a specific event. Returns all markets belonging to the event.
get_featured_marketsreadGet featured or promoted markets. Returns curated list of important markets.
get_liquidityreadGet available liquidity in USD for a market.
get_market_detailsreadGet complete market information including metadata, tokens, volume, and liquidity.
get_market_holdersreadGet top position holders for a market. Note: Requires authenticated access.
get_market_volumereadGet volume statistics for different timeframes (24h, 7d, 30d, all-time).
get_open_ordersreadGet all active/open orders, optionally filtered by market.
get_order_historywriteGet historical orders with optional filters for market and date range.
get_order_statuswriteCheck status and fill details of a specific order.
get_orderbookwriteGet complete order book with bids and asks arrays.
get_price_historyreadGet historical price data (OHLC). Note: Limited availability via public API.
get_sports_marketsreadGet sports betting markets. Optionally filter by specific sport type.
get_spreadreadGet current spread (difference between bid and ask prices).
get_trending_marketsreadGet markets with highest trading volume in specified timeframe. Returns top markets sorted by volume.
search_marketsreadSearch markets by text query, slug, or keywords. Returns markets matching the search criteria.
04

Trust audit

CAUTIONgrade C · trust 71/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/polymarket_mcp/auth/client.py:164
logger.info(f"API credentials created: {creds.api_key[:8]}...")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/polymarket_mcp/server.py:696
logger.debug(f"POLYMARKET_API_KEY={api_key[:8]}...")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_client_auth_offline.py:57
api_key="0xcreated0000000000000000000000000000000",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_error_log_sanitization_r2_offline.py:279
api_key="synthetic-key-000000",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server_lifecycle_offline.py:265
api_key="synthetic-key-000000",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codecov.yml
.codecov.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.secrets.baseline
.secrets.baseline
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
test_web_dashboard.py:105
__import__(module)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_console_entry_offline.py:131
module = importlib.import_module(mod)
LOWNetwork egress · net.env_exfil · CWE-200, CWE-319
tests/test_web_app_offline.py:74
".env" ... Websocket
Why it matters. reads secrets in the same file that sends data out
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_url_config_contract.py:52
GAMMA_OVERRIDE = "http://127.0.0.1:9999"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_url_config_contract.py:53
CLOB_OVERRIDE = "http://127.0.0.1:8443"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_mcp_conformance_e2e_offline.py:121
_INOPERATIVE_PROXY = "http://127.0.0.1:1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_mcp_stdio_e2e_offline.py:121
_INOPERATIVE_PROXY = "http://127.0.0.1:1"
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/test_safety_adversarial.py:303
result = await tools.create_limit_order("m1", "ВUY", 0.5, 10.0)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/test_safety_adversarial.py:306
assert result["error"] == "Side must be BUY or SELL, got ВUY"
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/test_safety_adversarial.py:695
{"token_id": "t1", "outcome": "Вuy"},
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
FAQ.md:445
2. Variable is set: `cat .env | grep POLYGON`
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTALLATION.md:418
cat .env | grep DEMO_MODE
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
TEST_INSTALLATION.md:49
cat .env | grep DEMO  # DEMO_MODE=true present
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
TEST_INSTALLATION.md:92
cat .env | grep -E "POLYGON_PRIVATE_KEY|POLYGON_ADDRESS"
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
TEST_INSTALLATION.md:96
cat .env | grep DEMO
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION.md:40
curl -sSL https://raw.githubusercontent.com/caiovicentino/polymarket-mcp-server/main/quickstart.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION_SUMMARY.md:107
curl -sSL https://raw.githubusercontent.com/.../quickstart.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha e670de3259e8full audit observations/trust-audit/mcp-server/caiovicentino__polymarket-6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28e670de3259e8CAUTIONC71first audit
06

Questions

What is the Polymarket MCP server?

🤖 AI-Powered MCP Server for Polymarket - Enable Claude to trade prediction markets with 45 tools, real-time monitoring, and enterprise-grade safety features

What tools does Polymarket expose?

24 in total: 20 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Polymarket safe to connect to an agent?

With care. The audit graded it C (71/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Polymarket need?

It reads POLYGON_PRIVATE_KEY, POLYMARKET_API_KEY and POLYMARKET_PASSPHRASE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Polymarket run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as polymarket-mcp.

How current is this page?

The grade is for one exact copy of the source (e670de3259e8), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement