investoday-finance-data
Warn
Audited by Snyk on Mar 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly sends queries to the external Investoday API (https://data-api.investoday.net) as described in SKILL.md and the references (e.g., references/公告.md and references/大模型语料.md) to fetch public news, company announcements and interactive Q&A (user-generated) which the agent is expected to read and use to drive analysis and decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata