Arcanea Lore Master

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill routinely ingests and interprets other creators' user-generated "Essences" via the Discovery/Remix features (e.g., the "Remix Feed", "Constellation" discovery feed, and translation/fusion/iteration remix workflows), which are untrusted third‑party contributions the agent is expected to read and act on.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill defines an on-platform economy with native tokens and explicit blockchain/transaction features: ARC (spendable "creative energy" currency), NEA governance tokens, "ARC/NEA on blockchain", NFT minting capabilities, "Collaboration Contracts
  • Smart contracts for shared ownership", explicit spend/earn flows ("Spend ARC", "Creator keeps 70% of sales revenue"), and paid subscription tiers ($20/month, $100/month). These are not generic utilities — they are specific financial/crypto features that imply token transfers, minting/smart-contract operations, and payment flows. Per the rule (crypto/blockchain tooling qualifies), this is Direct Financial Execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 03:00 AM