dapp-kalshi

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Kalshi trading purpose matches the high-level commands, but the core execution path is not coherent with the publisher identity: it installs and updates plugin-store from an unrelated personal GitHub raw script, then forwards Kalshi API credentials to that external CLI. Because the skill enables real-money trading and relies on an unverifiable installed tool for authenticated actions, the risk is high even without proof of active exfiltration.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/purong-huang-1121%2Fskills-store%2Fdapp-kalshi%2F@51258818eaff63f6faf3ded1d8d524a3b288fd29