Back to skill

Security audit

Kalshi Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is for real Kalshi trading and is disclosed, but it needs review because it installs an unpinned global CLI and enables live financial actions with weak safety guidance.

Install only if you intentionally want an agent-accessible tool that can read your Kalshi account data and place or cancel real orders. Pin and inspect the kalshi-cli version first, avoid running the installer with elevated privileges, lock down ~/.kalshi and key files to owner-only permissions, and require explicit human approval for every trade; do not use --force in agent workflows.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
install.sh:5
Finding

Unpinned Global Installation of a Security-Sensitive Third-Party Package

Content
View full analysis
/dev/null; then echo "📦 Installing kalshi-cli from npm..." npm install -g kalshi-cli else echo "✅ kalshi-cli is already installed" fi ``` The same unpinned installation is documented in `SKILL.md` and `README.md`: ```bash npm install -g kalshi-cli ``` ### Technical Analysis The installer resolves the current `kalshi-cli` release from the npm registry at installation time. It does not specify an exact audited version, verify a package integrity digest, validate package provenance, or use a lockfile. Consequently, the code executed by the installation can differ from the code reviewed with this Skill. npm packages can execute lifecycle scripts during installation. The globally installed CLI also subsequently receives access to the user's Kalshi authentication material and is authorized to place financial trades. Global installation increases the potential impact. Depending on the npm configuration and the way the script is invoked, package installation scripts may execute with the current user's privileges or elevated privileges. The external `kalshi-cli` implementation was not included in the audited project, so its behavior could not be verified. This finding does not establish that the current npm package is malicious. It identifies an unsafe trust and update model for a component with credential access and financial transaction capabilities. ### Attack Path 1. An attacker compromises the npm publisher account, package repository, release workflow, or another part of the package supply chain. 2. The attacker publishes a malicious release under the existing `kalshi-cli` package name. 3. A user runs `install.sh` or ...[truncated 1207 chars]
Remediation
View remediation
``` 2. Verify the downloaded package against an expected integrity digest and validate npm provenance before installation. 3. Review whether the package requires lifecycle scripts. Use `--ignore-scripts` if they are not essential. 4. Prefer a project-local or otherwise isolated installation over a global installation. 5. Do not instruct users to run the installer with `sudo` or as root. 6. Record the reviewed version and expected integrity value in the Skill package. 7. Re-audit the external CLI whenever the pinned version is updated, with particular attention to: - Credential loading and storage - Network destinations - Request signing - Trade confirmation behavior - Shell execution - npm lifecycle scripts 8. Consider requiring explicit user approval before installing external code rather than installing it automatically. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:14
Finding

Credential Files and Directory Are Created Without Restrictive Permissions

Content
View full analysis
"$HOME/.kalshi/.env" << 'EOF' # Kalshi API Configuration # Get credentials at: https://kalshi.com/api KALSHI_ACCESS_KEY=your_access_key_here EOF echo "📄 Created ~/.kalshi/.env — edit it with your API key" fi ``` The README also recommends creating the file without setting secure permissions: ```bash mkdir -p ~/.kalshi # Place your RSA private key at ~/.kalshi/private_key.pem # Set your access key echo 'KALSHI_ACCESS_KEY=your_access_key_id' > ~/.kalshi/.env ``` ### Technical Analysis Neither the installer nor the documentation sets a restrictive umask or explicitly applies permissions to the credential directory and files. Under a common `022` umask: - `~/.kalshi` may be created with mode `0755`. - `~/.kalshi/.env` may be created with mode `0644`. - A user-created `private_key.pem` may likewise remain readable by other local users if copied or created under permissive defaults. The access-key identifier in `.env` is only one component of Kalshi authentication and may not independently authorize API requests. However, exposing it unnecessarily weakens credential confidentiality. Exposure becomes critical if the RSA private key is also created with permissive permissions or if additional secrets are later added to `.env`. The README command uses shell redirection with `>`, which overwrites an existing `.env` file. This can cause accidental loss of configuration or credentials. Credential access is necessary for authenticated market and trading functionality. World-readable or group-readable credential storage is not necessary and violates least-privilege principles. ### Attack Path 1. A user ...[truncated 1596 chars]
Remediation
View remediation
"$HOME/.kalshi/.env" <<'EOF' # Kalshi API Configuration # Get credentials at: https://kalshi.com/api KALSHI_ACCESS_KEY=your_access_key_here EOF fi ``` 4. Validate and correct existing permissions: ```bash chmod 700 "$HOME/.kalshi" chmod 600 "$HOME/.kalshi/.env" [ ! -f "$HOME/.kalshi/private_key.pem" ] || chmod 600 "$HOME/.kalshi/private_key.pem" ``` 5. Verify that paths are owned by the current user and are not symbolic links before creating or modifying sensitive files. 6. Update the README to use non-destructive creation logic rather than unconditional `>` redirection. 7. Warn users not to store the private key in source repositories, shell history, shared directories, backups without encryption, or broadly readable locations. 8. Where supported, use an operating-system credential store or protected key-management mechanism instead of a plaintext environment file. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description says this skill is a Kalshi prediction market agent that analyzes markets and executes trades via the Kalshi API. However, the supplied code chunk does not analyze markets or execute trades at all. It is only an installer/bootstrap script for a Kalshi CLI and local credential files. While setup for Kalshi access is related to the general domain, the actual behavior is materially different from the claimed primary purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 16)May include surrounding context.

sh
# Set up credentials directory
mkdir -p "$HOME/.kalshi"
if [ ! -f "$HOME/.kalshi/.env" ]; then
    cat > "$HOME/.kalshi/.env" << 'EOF'
# Kalshi API Configuration
# Get credentials at: https://kalshi.com/api

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 17)May include surrounding context.

sh
# Set up credentials directory
mkdir -p "$HOME/.kalshi"
if [ ! -f "$HOME/.kalshi/.env" ]; then
    cat > "$HOME/.kalshi/.env" << 'EOF'
# Kalshi API Configuration
# Get credentials at: https://kalshi.com/api

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
# Get credentials at: https://kalshi.com/api
KALSHI_ACCESS_KEY=your_access_key_here
EOF
    echo "📄 Created ~/.kalshi/.env — edit it with your API key"
fi

if [ ! -f "$HOME/.kalshi/private_key.pem" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 22)May include surrounding context.

sh
# Get credentials at: https://kalshi.com/api
KALSHI_ACCESS_KEY=your_access_key_here
EOF
    echo "📄 Created ~/.kalshi/.env — edit it with your API key"
fi

if [ ! -f "$HOME/.kalshi/private_key.pem" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 33)May include surrounding context.

sh
# Get credentials at: https://kalshi.com/api
KALSHI_ACCESS_KEY=your_access_key_here
EOF
    echo "📄 Created ~/.kalshi/.env — edit it with your API key"
fi

if [ ! -f "$HOME/.kalshi/private_key.pem" ]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

2. Configure API credentials

bash
mkdir -p ~/.kalshi
# Place your RSA private key at ~/.kalshi/private_key.pem

# Set your access key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly demonstrates commands that can execute real trades, including a concrete buy example, without any warning that these actions may spend funds and are potentially irreversible. In an agent skill context, operational examples are likely to be copied into automation flows, which increases the chance of unintended financial actions by a user or agent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The documented --force flag bypasses the confirmation prompt for placing trades, removing a key human safety check before executing financially sensitive actions. In the context of a trading skill that uses live API credentials and a local private key, this materially increases the risk of unintended, automated, or prompt-influenced order placement causing real monetary loss.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
# Sell (same syntax)
kalshi sell KXWO-GOLD-26-NOR 5 40 --side no

# Skip confirmation prompt
kalshi buy KXSB-26 10 68 --force

# Cancel an open order

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The script creates a persistent credentials directory under the user's home directory and stores API material there without explicitly enforcing restrictive permissions. Because the same directory is intended to hold both the API key and an RSA private key, weak default permissions or shared-user environments could expose long-lived secrets to other local users or processes.

Content

Scanner excerpt · install.sh (reported line 15)May include surrounding context.

sh
fi

# Set up credentials directory
mkdir -p "$HOME/.kalshi"
if [ ! -f "$HOME/.kalshi/.env" ]; then
    cat > "$HOME/.kalshi/.env" << 'EOF'
# Kalshi API Configuration

Static analysis

No suspicious patterns detected.