Kalshi Weather Trader

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real weather-trading skill, but it needs Review because it can use a Solana private key to place live financial trades and includes risky trading controls.

Install only if you are comfortable giving this skill a Simmer API key and a Solana wallet key that can sign real transactions. Use a dedicated low-balance wallet, start in dry-run mode, keep position and trade limits small, avoid --no-safeguards for live trading, and enable scheduling only when you intentionally want automated execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The manifest explicitly requires a base58 Solana private key to be supplied to the skill for automated trading, but it provides no prominent warning about the sensitivity of that credential or the financial consequences of granting signing authority. In the context of an auto-trading skill, this increases the risk that users expose a hot-wallet key to code that can place trades or potentially misuse funds if the implementation is compromised or behaves unexpectedly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal