Back to plugin

Security audit

Kalshi CLI

Security checks across malware telemetry and agentic risk

Overview

This plugin appears to be a bounded, read-only Kalshi query bridge with disclosed local CLI and account-data access.

Install this only if you intend to let OpenClaw run your local kalshi CLI for read-only market, order, and portfolio queries. Keep Kalshi private-key material out of tool parameters, approve the optional tool only for agents that should see this data, and prefer hosts satisfying the documented OpenClaw >=2026.7.1-2 requirement.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/runner.js:57
Evidence
execFile(binaryPath, argv, {