risk-desk
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/risk-desk.ts, the required runtime ingests outsider-authored free text from--positions <csv>/.cache/stocks-daily/positions_live_*.csvvialoadPositions()(reads raw CSV lines and parsesPosition/MarketValue/Unrealized_PnL/Typefields) and then incorporates those fields into sheet arming strings (e.g.,reason,dataSource,symbol).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata