Back to skill

Security audit

Fuku Predictions

Security checks for vulnerabilities and agentic risk

Overview

This real-money Kalshi trading skill is mostly coherent with its stated purpose, but it can store trading credentials, place live orders automatically, and install recurring scheduled trading with insufficient safeguards.

Review this carefully before installing. Use dry-run or approval mode by default, avoid enabling full-auto cron trading unless you understand the financial risk, protect or replace the plaintext `.env` credential storage, and verify exactly which Kalshi permissions and spending limits the API key has.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
scripts/setup.py:562
Finding

Persistent Scheduled Task Can Perform Unattended Real-Money Trading

Content
View full analysis
> {log_path} 2>&1" print(f"\nAdd this line to your crontab (crontab -e):") print(f"{cron_entry}") print("\nThis will run every 30 minutes from 9 AM to 11 PM") print("Logs will be saved to:", log_path) auto_add = input("\nAttempt to add to crontab automatically? (y/N): ").strip().lower() if auto_add in ("y", "yes"): try: import subprocess result = subprocess.run( ["crontab", "-l"], capture_output=True, text=True ) existing_cron = result.stdout if result.returncode == 0 else "" # Check if entry already exists if "kalshi-autopilot" in existing_cron or script_path in existing_cron: print("⚠️ Similar cron entry already exists. Please check manually.") else: new_cron = existing_cron + f"\n# Kalshi Autopilot\n{cron_entry}\n" proc = subprocess.Popen(["crontab", "-"], stdin=subprocess.PIPE, text=True) proc.communicate(new_cron) if proc.returncode == 0: print("✅ Cron job added successfully") else: print("❌ Failed to add cron job. Please add manually.") ``` ### Technical Analysis The setup wizard can modify the current user's crontab and create a scheduled task that survives completio ...[truncated 2161 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.py:232
Finding

Kalshi RSA Private Key Is Stored in Plaintext Without Enforced Owner-Only Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:25
Finding

Security-Critical Python Dependencies Are Installed Without Version or Hash Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (41)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill emphasizes local-only API key handling while also documenting use of an external prediction API. Even if the Kalshi key itself is not sent to that API, the description can mislead users into believing the skill's operation is entirely local except for Kalshi, obscuring third-party data flows and increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill emphasizes local-only API key handling while also documenting use of an external prediction API. Even if the Kalshi key itself is not sent to that API, the description can mislead users into believing the skill's operation is entirely local except for Kalshi, obscuring third-party data flows and increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill emphasizes local-only API key handling while also documenting use of an external prediction API. Even if the Kalshi key itself is not sent to that API, the description can mislead users into believing the skill's operation is entirely local except for Kalshi, obscuring third-party data flows and increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill emphasizes local-only API key handling while also documenting use of an external prediction API. Even if the Kalshi key itself is not sent to that API, the description can mislead users into believing the skill's operation is entirely local except for Kalshi, obscuring third-party data flows and increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill emphasizes local-only API key handling while also documenting use of an external prediction API. Even if the Kalshi key itself is not sent to that API, the description can mislead users into believing the skill's operation is entirely local except for Kalshi, obscuring third-party data flows and increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The markdown promotes autonomous trading, including a fully automatic mode, without a prominent warning about financial loss, order execution consequences, or the need for explicit opt-in. In a real-money trading context, this omission can lead users to enable hands-free execution without understanding that the agent may place irreversible or loss-generating trades.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/browse.py (reported line 35)May include surrounding context.

python
sys.exit(1)

_dir = os.path.dirname(os.path.abspath(__file__))
load_dotenv(os.path.join(_dir, "..", ".env"))
load_dotenv()

from kalshi_client import KalshiClient

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/browse.py (reported line 613)May include surrounding context.

python
sys.exit(1)

_dir = os.path.dirname(os.path.abspath(__file__))
load_dotenv(os.path.join(_dir, "..", ".env"))
load_dotenv()

from kalshi_client import KalshiClient

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kalshi_client.py (reported line 38)May include surrounding context.

python
sys.exit(1)

_dir = os.path.dirname(os.path.abspath(__file__))
load_dotenv(os.path.join(_dir, "..", ".env"))
load_dotenv()

from kalshi_client import KalshiClient

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kalshi_client.py (reported line 441)May include surrounding context.

python
sys.exit(1)

_dir = os.path.dirname(os.path.abspath(__file__))
load_dotenv(os.path.join(_dir, "..", ".env"))
load_dotenv()

from kalshi_client import KalshiClient

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.py (reported line 167)May include surrounding context.

python
sys.exit(1)

_dir = os.path.dirname(os.path.abspath(__file__))
load_dotenv(os.path.join(_dir, "..", ".env"))
load_dotenv()

from kalshi_client import KalshiClient

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

By default, running the script can place real Kalshi orders immediately without a final confirmation gate, strong warning, or safe-by-default mode. In the context of an autonomous trading skill with locally stored API credentials, this materially increases the risk of accidental financial loss from mis-invocation, prompt/agent misuse, bad configuration, or faulty upstream scanner output.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kalshi_client.py (reported line 36)May include surrounding context.

python
print("Install with: pip install httpx cryptography python-dotenv")
    sys.exit(1)

# Load .env from skill root (one level up from scripts/)
_script_dir = os.path.dirname(os.path.abspath(__file__))
_env_path = os.path.join(_script_dir, "..", ".env")
load_dotenv(_env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.py (reported line 272)May include surrounding context.

python
print("Install with: pip install httpx cryptography python-dotenv")
    sys.exit(1)

# Load .env from skill root (one level up from scripts/)
_script_dir = os.path.dirname(os.path.abspath(__file__))
_env_path = os.path.join(_script_dir, "..", ".env")
load_dotenv(_env_path)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The wizard tells users their API keys are 'never transmitted externally,' but then immediately uses those credentials to make a live Kalshi API request during connection testing. This is a misleading security claim that can cause users to disclose high-value trading credentials under false assumptions, especially dangerous in a trading skill handling real funds.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Writing the private key and API identifier into .env constitutes handling sensitive credentials in plaintext local storage. In a financial trading skill, compromise of these secrets could directly enable account access and unauthorized orders, making the credential-handling risk more severe than in a low-stakes app.

Content

Scanner excerpt · scripts/setup.py (reported line 260)May include surrounding context.

python
try:
            set_key(self.env_path, "KALSHI_API_KEY_ID", api_key_id)
            set_key(self.env_path, "KALSHI_PRIVATE_KEY", private_key)
            print("✅ Credentials saved to .env file")
        except Exception as e:
            print(f"❌ Error saving credentials: {e}")
            return False

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and documents capabilities that require sensitive tool access (environment secrets, filesystem writes, network access, and shell execution) but does not declare any explicit tool scope or permission boundaries. In a trading skill that can access API credentials and place financial orders, missing scope declarations increases the chance of over-broad invocation and unauthorized use of powerful capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad enough to match general trading, sports prediction, or market-analysis requests, which can cause the skill to trigger outside a narrow Kalshi-specific context. In a skill capable of scanning markets and potentially placing trades, over-broad routing increases the risk of unintended invocation and action in financially sensitive workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a JSON manifest file, so vague-trigger review applies. The name and description describe a broad capability for 'Player-level analysis' and 'props' but do not specify explicit trigger phrases, invocation conditions, or exclusions, which could allow unintended activation in general sports-analysis contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document includes a concrete live order placement example against a trading API without any nearby warning that it can execute real-money trades. In a skill explicitly designed for conversational and potentially autonomous Kalshi trading, this omission increases the chance that downstream agents or developers will copy the snippet into production flows without adding confirmation, simulation mode, or user consent safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file presents automated real-money trading strategies and performance framing before prominently warning about financial loss, drawdowns, or the possibility of autonomous execution mistakes. In a skill designed for conversational trading and autopilot behavior, delayed disclosure can cause users to underestimate risk and consent to unsafe actions without informed understanding.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/agent_interface.py (reported line 118)May include surrounding context.

python
"--mode", "approve"
        ]
        
        result = subprocess.run(
            cmd, 
            cwd=SCRIPT_DIR,
            capture_output=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function saves user-supplied trading profile data to disk and then reveals the filesystem save path back to the user, but there is no consent prompt, retention notice, or minimization of stored data. In a conversational agent context, users may not expect persistent storage of their preferences, and exposing local paths can leak environmental details useful for later targeting or privacy violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s auto mode executes live Kalshi orders directly from cron-driven logic without any execution-time user confirmation, interactive warning, or second-factor approval. In the context of a conversational trading skill that can operate autonomously, this materially increases the chance of unauthorized, unintended, or manipulated real-money trades if the profile, market data, scheduling, or upstream agent behavior is wrong or abused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kalshi_client.py (reported line 53)May include surrounding context.

python
automatic retries, and pagination support.
    """

    BASE_URL = "https://api.elections.kalshi.com/trade-api/v2"
    SIGN_PREFIX = "/trade-api/v2"  # Kalshi requires full path in signature
    MAX_RETRIES = 2
    RETRY_DELAY = 1.0  # seconds between retries

Static analysis

No suspicious patterns detected.