T09 · Insecure Skill Coding Practices
- Location
scripts/scan-edges.js:74- Finding
Index-Based Odds Mapping Can Invert Financial Recommendations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Kalshi trading toolkit, but it exposes live financial actions and fragile market-matching logic without the safeguards its own docs describe.
Review this carefully before installing. Use read-only or test credentials where possible, avoid putting private keys directly into shell history, and do not let an agent place or cancel real Kalshi orders through this skill unless you have added explicit confirmation, dry-run defaults, order-size limits, exposure checks, and reliable market-participant matching.
scripts/scan-edges.js:74Index-Based Odds Mapping Can Invert Financial Recommendations
scripts/scan-edges.js:82Ambiguous Surname Matching Can Associate Odds with the Wrong Kalshi Market
scripts/kalshi-auth.js:91Live Order Function Does Not Enforce Documented Trading Safety Controls
Referenced artifact was not completely inspected
node scripts/scan-edges.js --category tennis
Referenced artifact was not completely inspected
node scripts/scan-edges.js --category tennis
The skill describes capabilities that rely on environment variables and outbound network access, but it does not declare any explicit tool scope or permissions boundaries. In an agent setting, this increases the chance that a host will grant broader-than-necessary access, enabling unintended credential access or live API interaction without clear user consent.
The skill promotes live order execution and credential handling for a real-money trading platform without an explicit warning that actions may place actual trades and cause financial loss. In this context, omission of a risk warning is dangerous because users or agents may treat examples as safe defaults and trigger irreversible market actions.
The quick-start instructions tell users to export an RSA private key directly in the shell and then run trading commands, but they do not warn about shell history, process inspection, logging, or safer secret-storage methods. This can expose long-lived credentials that enable unauthorized API access and potentially fraudulent trading on the user's account.
The module exposes placeOrder and cancelOrder as directly callable functions that execute real trading actions immediately, with no confirmation gate, dry-run mode, policy check, or explicit safeguard against accidental invocation. In the context of an agent skill for automated prediction-market trading, this increases the risk that a prompt, logic error, or unintended tool call can place or cancel live orders and cause financial loss.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// Get today's scheduled events from Sofascore
const today = new Date().toISOString().split('T')[0];
const scheduled = await fetch(`https://api.sofascore.com/api/v1/sport/tennis/scheduled-events/${today}`);
if (!scheduled?.events) { console.log('No events found'); return; }
// Get Kalshi tennis series
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// Get today's scheduled events from Sofascore
const today = new Date().toISOString().split('T')[0];
const scheduled = await fetch(`https://api.sofascore.com/api/v1/sport/tennis/scheduled-events/${today}`);
if (!scheduled?.events) { console.log('No events found'); return; }
// Get Kalshi tennis series
No suspicious patterns detected.