I dont think this is malicious, it just stood out to me.
What is this doing exactly?
self.sign_url = "https://builder-signing-server.vercel.app/sign"
And what would you do if you dont want to rely on a third party signing app? Can you do it with polymarket builder api and set this up oneself?