stock-query
Warn
Audited by Snyk on Apr 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's scripts (notably scripts/sq.sh, _enrich_detail_json, and scripts/fmt.sh) explicitly fetch and ingest live data from public third‑party sites such as qt.gtimg.cn, hq.sinajs.cn, push2.eastmoney.com, query1.finance.yahoo.com, fundgz.1234567.com.cn and api.fund.eastmoney.com (see SKILL.md, skill.yaml and scripts/), and those responses are parsed and directly influence routing, formatting, MA calculations and portfolio actions—so untrusted external content can materially affect agent behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata