Back to skill

Security audit

Cross-Market Pricer

Security checks for vulnerabilities and agentic risk

Overview

The skill’s odds-comparison purpose is coherent, but its instructions tell agents to insert user-controlled values directly into shell and Python commands, which creates a real code-execution risk.

Review before installing. The skill is not deceptive and does not install persistent code, but use it only if your agent will treat all event names, categories, tickers, platform names, and odds values as untrusted data and rewrite the examples to pass values via URL encoding, argv, stdin, or JSON instead of interpolating them into commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Shell Command Injection Through Unvalidated URL Placeholder Substitution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:111
Finding

Python Code Injection in Generated Cross-Market Comparison Script

Content
View full analysis
Remediation
View remediation
100: raise ValueError("Invalid platform name") for key in ("yes_prob", "no_prob"): value = data[key] if isinstance(value, bool) or not isinstance(value, (int, float)): raise ValueError("Probability must be numeric") if not math.isfinite(value) or not 0.0 <= value <= 1.0: raise ValueError("Probability is out of range") ``` - If command-line arguments must be used, access them through `sys.argv`; do not insert them into Python source. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:160
Finding

Python Code Injection in Quick Odds Conversion Template

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
Replace INPUT_VALUE with the user's value (e.g., "-150", "0.62", "$0.58").

## Output Rules

1. Always show implied probability as the primary format (3 decimal places, e.g., 0.620)
2. Include American odds equivalent alongside probability for sportsbook-familiar users

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Pull American odds from The Odds API and convert to implied probability inline:

bash
curl -s "https://api.the-odds-api.com/v4/sports/SPORT_KEY/odds?apiKey=$ODDS_API_KEY&regions=us&markets=h2h&oddsFormat=american" \
  | jq '[.[] | {
    event: "\(.away_team) vs \(.home_team)",
    start: .commence_time,

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Pull contract prices from Kalshi's public market data API:

bash
curl -s "https://api.elections.kalshi.com/trade-api/v2/markets?status=open&limit=10&series_ticker=SERIES_TICKER" \
  | jq '[.markets[] | {
    event: .title,
    source: "kalshi",

Static analysis

No suspicious patterns detected.