ai-quant-engineering

Warn

Audited by Snyk on Apr 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly describes fetching external market and news content (e.g., tools/market_data.py, tools/news_sentiment.py and the Kraken API integration, plus the MCP tool "get_news_sentiment") which the agents ingest and use in orchestration/decision loops, so untrusted third‑party content can materially influence agent actions.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes trading execution components and an exchange API integration. It lists a "Trade Executor" (order submission and tracking), an "Auto Trader" (autonomous trading loop), a "Portfolio Service" (rebalancing), and specifically mentions tools/kraken_api.py — Kraken exchange API integration. These are concrete, finance-specific interfaces for submitting market orders / interacting with a crypto exchange (not generic browser or HTTP tooling). Therefore it provides direct financial execution capability.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Issues
2
Security Audit — snyk — ai-quant-engineering