Back to skill

Security audit

Kalshi Crypto Volatility Skew Trader

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed live trading skill, but its exit logic can sell BTC positions it did not create, so it needs Review before installation.

Install only after reviewing the trading authority you are granting. Use paper mode first, provide live credentials only in an isolated account or wallet with limited funds, and avoid running --live until exit logic is fixed to sell only positions positively tagged as created by this skill. Pin and review simmer-sdk before using production credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
trader.py:437
Finding

Live exit logic can liquidate BTC positions not created by this Skill

Content
View full analysis
= EXIT_THRESHOLD: found += 1 log(f" EXIT: {question} price={price:.2f} >= {EXIT_THRESHOLD:.2f}") ctx = get_market_context(market_id) ok, reasons = check_safeguards(ctx) if not ok: log(f" Skipped: {'; '.join(reasons)}") continue if not dry_run: result = execute_trade( market_id, "sell", shares, reasoning=f"Exit: price {price:.2f} >= threshold {EXIT_THRESHOLD:.2f}", ) ``` ### Technical Analysis The position-selection condition uses a logical `or`. A position is therefore eligible for liquidation when either: 1. Its source metadata contains this Skill's `TRADE_SOURCE`; or 2. Its question contains the keyword `bitcoin` or `btc`. The second condition is not an ownership or authorization check. It includes BTC positions created manually, by another Skill, or by an unrelated trading strategy. Once such a position reaches `EXIT_THRESHOLD`, live mode calls `execute_trade()` with the `"sell"` action and the position's full reported share count. The market-context safeguards check resolution status, flip-flop warnings, time to resolutio ...[truncated 1358 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
clawhub.json:7
Finding

Unpinned third-party SDK is entrusted with high-value trading credentials

Content
View full analysis
SDK tab") sys.exit(1) venue = os.environ.get("TRADING_VENUE", "kalshi") _client = SimmerClient(api_key=api_key, venue=venue, live=live) return _client ``` ### Technical Analysis The project declares `simmer-sdk` without an exact version or integrity hash. Package installation can consequently resolve to a future release that was not part of this audit. The imported package is passed `SIMMER_API_KEY` and performs the Skill's network and trading operations. This gives dependency code access to a high-value credential and the ability to alter API requests or trading behavior. The project metadata also declares `SOLANA_PRIVATE_KEY` as a required environment variable, although the audited project code does not directly read that variable. No evidence establishes that the currently published dependency is malicious. The confirmed weakness is that installation is not reproducible and does not constrain the security-sensitive package to an audited artifact. ### Attack Path 1. An attacker compromises the upstream package publisher, distribution account, or release pipeline, or a future release is otherwise mal ...[truncated 1197 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially understates operational behavior by omitting live-trading reliance on SOLANA_PRIVATE_KEY and additional capabilities such as configuration mutation, account/position access, and possible journaling or external resource interactions. This is dangerous because users and orchestration systems may approve or auto-run the skill under an incomplete trust model, exposing funds, credentials, and account state to actions they did not knowingly authorize.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest requests SOLANA_PRIVATE_KEY even though the skill is described as a Kalshi BTC volatility-skew trader and its stated purpose does not justify Solana wallet access. Unnecessary collection of a blockchain private key materially increases the blast radius: if the skill, its dependencies, or surrounding execution environment are compromised, a live wallet secret could be exposed or misused.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Access to a Solana private key is unjustified by the skill's advertised Kalshi trading function, making the secret request suspicious and over-privileged. In this context, the mismatch makes the skill more dangerous because users may provide a highly sensitive credential unrelated to the expected trading workflow, enabling theft of on-chain assets if mishandled.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises required environment variables and live-trading credentials but does not declare any explicit tool scope or permission boundary. In an agent ecosystem, missing scope metadata can cause the runtime or user to grant broader access than intended, especially for high-value secrets like SIMMER_API_KEY and SOLANA_PRIVATE_KEY.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest requests a sensitive private key and supports automated execution without any warning about credential handling, signing authority, or live trading risk. Even if the key were somehow legitimate, the absence of explicit disclosure and safety messaging increases the chance that users will unknowingly expose valuable secrets or enable unintended financial actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill presents itself as a Kalshi trader, but the live-mode docstring explicitly states execution occurs via DFlow/Solana and the client abstraction routes through Simmer infrastructure rather than directly to Kalshi. In a trading skill that handles real funds and requires a private key, this mismatch is dangerous because operators may authorize wallet-backed execution under incorrect assumptions about venue, custody path, or settlement flow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring claims the function checks open BTC vol-skew positions, but the implementation broadens scope to any BTC position based on question text. In a live trading context, misleading documentation increases operational risk because reviewers may approve code believing exits are strategy-scoped when the function can act on unrelated holdings.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The position filtering logic includes any BTC-labeled position, not only positions opened by this strategy, because it matches either the strategy source tag or generic bitcoin/btc keywords in the question. In context, the exit logic can sell positions from unrelated BTC strategies or manual trades once price thresholds are met, causing unintended liquidation of assets outside this skill's scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The stated purpose is to analyze volatility skew and trade relevant markets. Adding a CLI path that persists configuration changes via update_config gives the skill a settings-management capability that is not mentioned in the manifest and is not essential to the trading function itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.