moomoo-stock-digest

Warn

Audited by Snyk on Jul 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Yes—during Step 2 (“Call the News API”) and Step 3 (“From the retrieved items”), the skill ingests free text fields like title (and likely other readable fields returned in data) from a runtime-fetched public news/search endpoint (https://ai-news-search.moomoo.com/news_search), which can contain outsider-authored content intended to influence the model.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 25, 2026, 05:42 AM
Issues
1
Security Audit — snyk — moomoo-stock-digest