financial-report-analyzer
Warn
Audited by Snyk on Apr 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill uploads and parses arbitrary third-party financial reports through SoMark (see financial_report_analyzer.py posting to ASYNC_URL and SKILL.md's "After the script finishes, read the generated Markdown and perform structured analysis"), so the agent ingests untrusted/public documents and must read/interpret them as part of its required workflow, which can materially influence analysis and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata