Kalshi Fed Temporal Mono Trader

PassAudited by VirusTotal on Apr 7, 2026.

Findings (1)

The skill bundle implements a legitimate-looking arbitrage strategy for Kalshi Fed rate markets but is classified as suspicious due to its requirement for a high-value credential (SOLANA_PRIVATE_KEY) and its dependency on an external package (simmer-sdk). While trader.py does not explicitly exfiltrate the key, the script's logic delegates trade execution to the third-party SDK, which creates a significant supply-chain risk for credential theft. The SKILL.md and clawhub.json files explicitly prompt the user to provide this private key, which is a high-risk behavior in the context of unvetted agent skills.