Back to skill

Security audit

Kalshi Command Center

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Kalshi trading tool, but its live order authority is paired with incomplete risk controls and unsafe maintenance/loading behavior that users should review carefully.

Install only if you are comfortable giving this skill access to Kalshi credentials and live order placement. Treat the advertised $50 daily loss cutoff and 100-contract cap as unreliable until fixed, use manual review before every trade, protect the private key and logs with restrictive permissions, and avoid running execute unless you trust any local Kalshalyst code it may load.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kalshi_commands.py:331
Finding

Advertised Daily-Loss and Aggregate Position Limits Are Not Enforced

Content
View full analysis
MAX_SINGLE_TRADE_COST: return f"❌ Trade cost ${cost:.2f} exceeds max ${MAX_SINGLE_TRADE_COST:.2f} per trade." if quantity > MAX_POSITION_SIZE: return f"❌ Quantity {quantity} exceeds max {MAX_POSITION_SIZE} contracts per trade." return None ``` The incomplete risk check is invoked before buy orders at `scripts/kalshi_commands.py:933-941`: ```python amount = quantity * price_cents / 100.0 if action == "buy": risk_err = _check_risk(amount, quantity) if risk_err: _trade_audit("trade_blocked", { "ticker": ticker, "side": side, "quantity": quantity, "price_cents": price_cents, "reason": risk_err, }) return risk_err ``` ### Technical Analysis `MAX_DAILY_LOSS` is declared as a kill switch but is never evaluated by `_check_risk()`. The function only checks the estimated cost and quantity of the current order. The quantity check is also a per-order limit rather than an aggregate position limit. It does not obtain the existing position or include resting orders when determining projected exposure. Consequently, multiple individually valid orders can create a position substantially larger than 100 contracts. This conflicts with the hard-limit claims in `SKILL.md:218-224` and `references/risk-limits.md:5-14`. Users or agents may therefore authorize trades under the incorrect assumption that cumulative loss and position controls ...[truncated 1600 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/kalshi_commands.py:1141
Finding

Dynamic Execution of Unverified Python from External Skill Paths

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description promises a $50 daily loss cutoff, but the code only defines MAX_DAILY_LOSS and never enforces it before placing trades. In an automated trading skill, this creates a dangerous mismatch between documented safety guarantees and actual behavior, allowing cumulative losses well beyond the stated stop limit.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script dynamically locates, imports, and executes Python code from external local paths during trade sizing via importlib and exec_module. Any attacker who can modify those searched files or influence the local skill directory can achieve arbitrary code execution in the context of a trading command that also has access to API credentials and can place orders.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that inherently require network access, environment-variable access, and file read/write, but it does not declare an explicit tool scope or permission boundary. In an agent ecosystem, that omission weakens least-privilege controls and can let a trading skill access credentials, modify local files, or perform network actions beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents live buy, sell, and execute commands for real prediction-market orders but does not place a prominent warning that these commands can create real financial obligations. In an autonomous or semi-autonomous agent setting, that omission increases the chance of accidental order placement or user misunderstanding, especially because the commands are presented as routine examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The credential setup section tells users where to place API key identifiers and private key paths, but it does not clearly warn them to protect private key material, avoid printing or sharing secrets, and enforce restrictive file permissions. For a financial trading skill, mishandled credentials could allow unauthorized account access and order placement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bug-fix protocol instructs the agent to edit source files on disk, update installed copies, and even stage git commits, which is not necessary for ordinary Kalshi trading operations. This expands the skill from a trading interface into a self-modifying/persistence-capable component, creating a path for unauthorized code changes, persistence, or supply-chain tampering if the agent is tricked or compromised.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

The instruction that the agent must write fixes to source files on disk for future scheduled runs is a direct persistence mechanism. In the context of an agent skill, persistence materially raises risk because any prompt-influenced or erroneous modification can survive the current session and affect later executions, potentially altering trading behavior or embedding malicious logic.

Content

Scanner excerpt · SKILL.md (reported line 518)May include surrounding context.

md
## Agent Bug-Fix Protocol

**CRITICAL**: When you (the agent) discover and fix a bug in any script during a conversation, you MUST write the fix to the source file on disk using file editing tools. Showing the fix in chat is NOT sufficient — the next scheduled run starts a fresh session and will not have your conversational fix.

Checklist after finding a bug:
1. Edit the actual `.py` file on disk (e.g., `~/skills/kalshi-command-center/scripts/kalshi_commands.py`)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document presents the $50 daily loss threshold as a hard limit enforced before order placement, but the same file says it is only applied via Kelly sizing if available. In a trading skill, inconsistent risk-control documentation can cause operators or downstream agents to believe a hard stop exists when it may not, leading to real-money trades continuing past the stated loss cap.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill documents persistent trade logging to a user home-directory file with detailed order metadata, but provides no warning about retention, local sensitivity, or access controls. While not an exploit by itself, this can expose trading history, strategy details, and potentially sensitive operational data to other local users, backups, or secondary tooling without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section labels the daily loss threshold as a 'hard stop' while other parts describe it as optional, Kelly-based, or dependent on available modules. That mismatch is dangerous because users may trust the system to stop trading automatically, when in practice the safeguard may be absent or partial, increasing the chance of uncontrolled losses.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This is a true issue: the documentation presents a 0-100 composite scoring model for live market scans, but the formulas and worked examples explicitly show the liquidity term can drive scores far above 100 unless normalized. In a trading command skill that ranks markets and may influence or trigger trade execution, inconsistent scoring documentation can cause operators or downstream components to misunderstand ranking behavior, calibrate thresholds incorrectly, and make unsafe trading decisions based on false assumptions about the implementation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.5 — 2 advisory(ies): CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2026-25645 (Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract)

Medium
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency pins requests to 2.32.5, and the finding cites a known vulnerability fixed in 2.33.0 involving insecure temporary file reuse in extract_zipped_paths(). Even if that helper is not always used, shipping a version with a known CVE is a real supply-chain risk, and in a trading skill that may handle external HTTP resources or archives, vulnerable utility paths can become reachable through future code changes or indirect use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kalshi_commands.py (reported line 65)May include surrounding context.

python
_CONFIG = _load_config()
_KALSHI = _CONFIG.get("kalshi", {})

BASE_URL = "https://api.elections.kalshi.com/trade-api/v2"
TICKER_NAMES = _KALSHI.get("ticker_names", {})

# Environment variable overrides

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kalshi_commands.py (reported line 603)May include surrounding context.

python
_CONFIG = _load_config()
_KALSHI = _CONFIG.get("kalshi", {})

BASE_URL = "https://api.elections.kalshi.com/trade-api/v2"
TICKER_NAMES = _KALSHI.get("ticker_names", {})

# Environment variable overrides

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The execute flow automatically places a live buy order from cached research once called, without a mandatory interactive confirmation step that restates ticker, side, quantity, and price. In a skill that can move money, this increases the chance of accidental or coerced trades, especially if upstream cache contents or user intent are ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.