institutional-sentiment-frontrunning

Fail

Audited by Snyk on Apr 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This content is high-risk: it explicitly instructs predicting non-public central-bank actions and drafting "front-run" trading strategies while cross-referencing dark-pool volume (implying use/exploitation of privileged or non-public market data), indicating intent to facilitate market manipulation/insider trading even though no explicit code-level backdoors or network-exfiltration routines are present.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md workflow (steps 1–5 and the examples) explicitly requires ingesting and analyzing public third‑party documents—e.g., "the latest Fed minutes", OPEC statements, and dark‑pool data—which are external/untrusted sources that can materially influence the agent's decisions and thus enable indirect prompt injection.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 19, 2026, 05:40 AM
Issues
2
Security Audit — snyk — institutional-sentiment-frontrunning