disclosure-notice-monitor
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow and data acquisition steps (references/data-queries.md and references/methodology.md) explicitly instruct running views/tools that fetch public third‑party sources (e.g., 巨潮资讯 / cninfo, 东方财富, AKShare stock_notice_report and announcement URLs) and then read/interpret those announcements to generate trading signals and recommendations, which clearly exposes the agent to untrusted public web content that can influence decisions.
Audit Metadata