pubmed-trends
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow ingests outsider-authored free text via user-supplied query/topic parameters that are sent to
https://pubmed.sekgen.xyz/api/v1/*endpoints (e.g.,/api/v1/snapshot?query=...,/api/v1/explore?topics=...) and uses the API response as LLM-readable research text.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly requires and documents cryptocurrency payments: it states "USDC micropayments on Base via x402", references the companion wallet skill (coinbase/agentic-wallet-skills x402) for payment commands, and shows concrete payment command examples like "awal x402 pay '...'" plus auth/payment handling. These are specific crypto/payment instructions (wallet/payment command integration), which constitute direct financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata