backtesting
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's Integration Notes and Usage Patterns explicitly allow specifying arbitrary public data URLs (e.g., "--data https://example.com/data.csv" and integrations with Yahoo Finance/Alpha Vantage), meaning the agent fetches and ingests open third‑party data that it must read and that can materially affect backtest decisions.
Audit Metadata