Back to skill

Security audit

Prediction Market Data

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only prediction market data client that uses a declared AIsa API key and disclosed HTTPS API calls, with minor privacy/documentation caveats around wallet lookups.

Install only if you are comfortable sending prediction-market queries, market IDs, wallet addresses, and your AIsa API key in Authorization headers to api.aisa.one. The skill appears read-only and does not trade or connect wallets, but wallet lookups can reveal financial activity to the API provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires an API key in the environment and directs execution of a Python client that makes outbound network requests, but it does not declare explicit tool scope such as permissions or allowed-tools. That creates a policy/visibility gap: an agent or platform may permit broader execution than reviewers expect, increasing the chance of unintended secret exposure or uncontrolled network use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This skill sends requests to an external domain, api.aisa.one, including user queries and potentially wallet addresses and market identifiers. External transmission is expected for an API client, but it still creates a real confidentiality and privacy boundary because user-supplied data leaves the local environment and is processed by a third party.

Content

Scanner excerpt · scripts/prediction_market_client.py (reported line 52)May include surrounding context.

python
class PredictionMarketClient:
    """Cross-Platform Prediction Market Data - AIsa API Client."""

    BASE_URL = "https://api.aisa.one/apis/v1"

    def __init__(self, api_key: Optional[str] = None):
        self.api_key = api_key or os.environ.get("AISA_API_KEY")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill transmits wallet addresses and related user-supplied identifiers to a third-party API, which can expose sensitive financial or behavioral metadata to an external service. In this skill context, that transmission is functionally necessary, but the lack of explicit disclosure or consent handling increases privacy risk, especially for wallet lookups, positions, activity, and PnL queries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline documentation for polymarket_orders claims the method retrieves trade history, which semantically differs from orders/order history. The implementation invokes /polymarket/orders, so the comment actively misstates the operation and could mislead reviewers or agents about what data is being accessed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The parser help text labels the 'orders' subcommand as trade history, but dispatch later calls client.polymarket_orders, which requests /polymarket/orders. This is an intent-documentation mismatch that can cause users or agents to request one kind of market data while receiving another.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file accesses a sensitive environment variable containing an API key, but provides no explicit warning beyond an error message when the variable is missing. Under the rule, access to credentials should have some disclosure in code comments, logs, prompts, or user-facing documentation within the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest describes a data-query skill for Polymarket and Kalshi markets, prices, orderbooks, positions, trades, and cross-platform comparisons. While outbound HTTP requests are expected for that purpose, reading secrets from process environment introduces credential-access behavior that is not stated in the manifest and is not user-visible functionality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.