@1247/trade-simulator

Warn

Audited by Snyk on Mar 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md and usage workflow explicitly state it "build[s] market state graph from live data" and list third‑party live sources (e.g., Coinglass/Hyperliquid social sentiment via lunar_coin), and that graph_context (built from that live data) is fed into LLM-driven profile generation, simulation reasoning, report generation and interviews (see mirofish_engine and profile_generator), so arbitrary public/web/user‑generated content can influence agent behavior and tools.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 15, 2026, 04:50 PM
Issues
1