grimoire-aave
Warn
Audited by Snyk on Apr 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly fetches Aave V3 public market and reserve data via the Grimoire venue CLI (see SKILL.md "Fetches Aave V3 public market data" and the recommended preflight referencing an RPC URL) and uses a reserves-snapshot command to emit agent-consumed "params:" blocks, so untrusted on-chain/public metadata could influence agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata