Back to skill

Security audit

SimpleFunctions

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent prediction-market CLI skill, but it gives agent-friendly access to real financial account functions without clear safety boundaries.

Install only if you intentionally want an agent-accessible tool connected to prediction-market accounts. Use read-only or limited credentials where available, verify whether configured Kalshi keys can place orders, avoid delegating trade execution without manual approval, and treat Telegram bot tokens and alert content as sensitive.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.