arkham-api
Warn
Audited by Snyk on Mar 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's SKILL.md explicitly instructs the agent to fetch and parse JSON from third-party Arkham API endpoints (e.g., curl "https://api.arkm.com/transfers", "https://api.arkm.com/intelligence/entity/*") and to use those responses (via jq) to drive analysis and follow-up actions, so untrusted external content can materially influence decisions.
Audit Metadata