kanchi-dividend-review-monitor
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill explicitly ingests public third‑party filing text (see Workflow step 1 and references/input-schema.md fields like filings.recent_text/latest_8k_text) and the runtime rule t4_governance_or_filing_alert in scripts/build_review_queue.py scans that untrusted filing text to set REVIEW/WARN states and trigger actions (e.g., create_review_ticket), so external content can materially influence behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata