finance-substrate

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). High: the dian-fill workflow generates agent-browser commands based on values computed from tax_projection.py, which in turn ingests outsider-authored free text from Gmail email bodies (e.g., Thera “You just received a payment!”) via scripts/gmail_collector.pyget_message_body() → regex parsing, and those extracted strings/values are then embedded into the LLM context when the agent runs the skill and uses the generated fill plan.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 03:33 PM
Issues
1
Security Audit — snyk — finance-substrate