yahoo-data-fetcher-hardened

Warn

Audited by Snyk on Apr 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's SKILL.md and index.js show it fetches live quotes from the public Yahoo Finance API (https://query1.finance.yahoo.com/v7/finance/quote) and parses/returns that third-party JSON into the conversation, meaning untrusted remote content is ingested and presented and could therefore influence downstream agent decisions or actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 06:35 PM
Issues
1
Security Audit — snyk — yahoo-data-fetcher-hardened