ave-data-wss

Warn

Audited by Snyk on Mar 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). This skill explicitly subscribes to and ingests live, public AVE Cloud WebSocket streams (wss://wss.ave-api.xyz) as described in SKILL.md and then has the agent read and act on those events (summarize, change subscriptions), which exposes it to untrusted, user-originated on-chain content that could carry malicious instructions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 06:13 AM
Issues
1