ai-quant-engineering
Warn
Audited by Snyk on Apr 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly describes fetching external market and news content (e.g., tools/market_data.py, tools/news_sentiment.py and the Kraken API integration, plus the MCP tool "get_news_sentiment") which the agents ingest and use in orchestration/decision loops, so untrusted third‑party content can materially influence agent actions.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes trading execution components and an exchange API integration. It lists a "Trade Executor" (order submission and tracking), an "Auto Trader" (autonomous trading loop), a "Portfolio Service" (rebalancing), and specifically mentions tools/kraken_api.py — Kraken exchange API integration. These are concrete, finance-specific interfaces for submitting market orders / interacting with a crypto exchange (not generic browser or HTTP tooling). Therefore it provides direct financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata