disclosure-notice-monitor

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow and data acquisition steps (references/data-queries.md and references/methodology.md) explicitly instruct running views/tools that fetch public third‑party sources (e.g., 巨潮资讯 / cninfo, 东方财富, AKShare stock_notice_report and announcement URLs) and then read/interpret those announcements to generate trading signals and recommendations, which clearly exposes the agent to untrusted public web content that can influence decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:23 AM