skills/adryanmoldokkr32-pixel/bionicbot-giant-sovereign-skills/institutional-sentiment-frontrunning/Snyk
institutional-sentiment-frontrunning
Fail
Audited by Snyk on Apr 19, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This content is high-risk: it explicitly instructs predicting non-public central-bank actions and drafting "front-run" trading strategies while cross-referencing dark-pool volume (implying use/exploitation of privileged or non-public market data), indicating intent to facilitate market manipulation/insider trading even though no explicit code-level backdoors or network-exfiltration routines are present.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md workflow (steps 1–5 and the examples) explicitly requires ingesting and analyzing public third‑party documents—e.g., "the latest Fed minutes", OPEC statements, and dark‑pool data—which are external/untrusted sources that can materially influence the agent's decisions and thus enable indirect prompt injection.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata