find-next-crypto-idea

Warn

Audited by Snyk on Apr 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's required workflow mandates "fresh research" using scripts/live_research.py and browser-first queries that fetch and inspect public web sources (explicitly calling out Helius Blog at https://www.helius.dev/blog, X/Twitter via bird.fast, GitHub and broader web searches in references/research-playbook.md and SKILL.md step 7), and those external, user-generated or public pages are then used to populate the research pack and directly influence scoring, ranking, and next actions—creating a clear path for indirect prompt injection from untrusted third-party content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 14, 2026, 03:26 PM
Issues
1