Back to skill

Security audit

Prediction Market Trader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kalshi trading toolkit, but it exposes live financial actions and fragile market-matching logic without the safeguards its own docs describe.

Review this carefully before installing. Use read-only or test credentials where possible, avoid putting private keys directly into shell history, and do not let an agent place or cancel real Kalshi orders through this skill unless you have added explicit confirmation, dry-run defaults, order-size limits, exposure checks, and reliable market-participant matching.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scan-edges.js:74
Finding

Index-Based Odds Mapping Can Invert Financial Recommendations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scan-edges.js:82
Finding

Ambiguous Surname Matching Can Associate Odds with the Wrong Kalshi Market

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kalshi-auth.js:91
Finding

Live Order Function Does Not Enforce Documented Trading Safety Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
node scripts/scan-edges.js --category tennis

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
node scripts/scan-edges.js --category tennis

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that rely on environment variables and outbound network access, but it does not declare any explicit tool scope or permissions boundaries. In an agent setting, this increases the chance that a host will grant broader-than-necessary access, enabling unintended credential access or live API interaction without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill promotes live order execution and credential handling for a real-money trading platform without an explicit warning that actions may place actual trades and cause financial loss. In this context, omission of a risk warning is dangerous because users or agents may treat examples as safe defaults and trigger irreversible market actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start instructions tell users to export an RSA private key directly in the shell and then run trading commands, but they do not warn about shell history, process inspection, logging, or safer secret-storage methods. This can expose long-lived credentials that enable unauthorized API access and potentially fraudulent trading on the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module exposes placeOrder and cancelOrder as directly callable functions that execute real trading actions immediately, with no confirmation gate, dry-run mode, policy check, or explicit safeguard against accidental invocation. In the context of an agent skill for automated prediction-market trading, this increases the risk that a prompt, logic error, or unintended tool call can place or cancel live orders and cause financial loss.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/scan-edges.js (reported line 49)May include surrounding context.

js
// Get today's scheduled events from Sofascore
  const today = new Date().toISOString().split('T')[0];
  const scheduled = await fetch(`https://api.sofascore.com/api/v1/sport/tennis/scheduled-events/${today}`);
  if (!scheduled?.events) { console.log('No events found'); return; }

  // Get Kalshi tennis series

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/scan-edges.js (reported line 76)May include surrounding context.

js
// Get today's scheduled events from Sofascore
  const today = new Date().toISOString().split('T')[0];
  const scheduled = await fetch(`https://api.sofascore.com/api/v1/sport/tennis/scheduled-events/${today}`);
  if (!scheduled?.events) { console.log('No events found'); return; }

  // Get Kalshi tennis series

Static analysis

No suspicious patterns detected.