econfin-idea-finder
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Step 1 “Global literature scan” uses runtime WebSearch/WebFetch to fetch SSRN pages, journal/seminar pages, and scraped seminar schedules; the fetched page text is then read/merged into
WORK_DIR/LITERATURE_SCAN.mdand subsequently injected into subagents via{{LITERATURE_SCAN_DIGEST}}foreconfin-proposal/novelty-check—i.e., outsider-authored web content becomes LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata