stock-portfolio

Warn

Audited by Snyk on Mar 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill directly ingests public third‑party market/news data via the yahoo_client (e.g., scripts like forecast.py: "推定利回り算出中(アナリスト目標・ニュース・センチメント取得)..." and multiple modules calling yahoo_client.get_stock_info/get_price_history/get_macro_indicators), and those external news/sentiment/price feeds are used to produce alerts and concrete actions (forecast/rebalance/adjust) that materially influence decisions—creating a clear avenue for indirect prompt injection from untrusted web content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 01:31 AM
Issues
1