stock-query

Warn

Audited by Snyk on Apr 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's scripts (notably scripts/sq.sh, _enrich_detail_json, and scripts/fmt.sh) explicitly fetch and ingest live data from public third‑party sites such as qt.gtimg.cn, hq.sinajs.cn, push2.eastmoney.com, query1.finance.yahoo.com, fundgz.1234567.com.cn and api.fund.eastmoney.com (see SKILL.md, skill.yaml and scripts/), and those responses are parsed and directly influence routing, formatting, MA calculations and portfolio actions—so untrusted external content can materially affect agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 14, 2026, 03:21 AM
Issues
1
Security Audit — snyk — stock-query