proposal-builder
Warn
Audited by Snyk on Sep 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow ingests outsider-authored meeting transcripts, emails, RFPs, and uploaded files, creating an indirect prompt injection risk via Step 1.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation includes instructions for generating invoices and payment links via integrated platforms (QuickBooks, Zoho Books, PayPal, Stripe) upon proposal acceptance (Step 7: "Generate the deposit invoice or payment link per the terms, through whichever the owner approves... Stripe
POST /v1/payment_linksorPOST /v1/invoicesviastripe_api_write"). This constitutes direct integration with financial and payment gateways to execute financial operations.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata