both-stock-analysis

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source: har-to-api Step 0 pulls a “snapshot” .data/[TICKER]/[YYYY-MM-DD].json that later steps (2–7) read/consume for narrative/valuation/earnings/technical inputs, and those facts originate from external financial data feeds that may include outsider-authored free text (e.g., filings/IR text) without the workflow selecting a specific trusted item first.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 02:06 PM
Issues
1
Security Audit — snyk — both-stock-analysis