aggregating-crypto-news
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill fetches and parses public RSS feeds from 50+ third‑party news sites (e.g., CoinDesk https://www.coindesk.com/arc/outboundfeeds/rss/, CoinTelegraph https://cointelegraph.com/rss, The Block https://www.theblock.co/rss.xml, Decrypt https://decrypt.co/feed and other sources listed in {baseDir}/config/sources.yaml), so the agent ingests and interprets untrusted public web content as part of its workflow.
Audit Metadata