arkham-api

Warn

Audited by Snyk on Mar 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's SKILL.md explicitly instructs the agent to fetch and parse JSON from third-party Arkham API endpoints (e.g., curl "https://api.arkm.com/transfers", "https://api.arkm.com/intelligence/entity/*") and to use those responses (via jq) to drive analysis and follow-up actions, so untrusted external content can materially influence decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 2, 2026, 05:04 PM