Security audit
SimpleFunctions
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent prediction-market CLI skill, but it gives agent-friendly access to real financial account functions without clear safety boundaries.
Install only if you intentionally want an agent-accessible tool connected to prediction-market accounts. Use read-only or limited credentials where available, verify whether configured Kalshi keys can place orders, avoid delegating trade execution without manual approval, and treat Telegram bot tokens and alert content as sensitive.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
