portfolio
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow for this skill triggers on Portfolio-related queries and operates on user-supplied requests to POST /onchain/v1/portfolio/positions (accountAddress/networkId/protocolIds), which are then used to orchestrate provider calls and aggregations, exposing the agent to outsider-authored free text from the request body.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata