account-intel
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required workflow, the agent actively fetches outsider-authored free text via external search/scraping APIs (YouTube search snippets from
mpp.orthogonal.com, Brave news results, and Exa web citation contents) using user-provided--name/--handle/--queryparameters, then ingests that text for synthesis.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly integrates payment rails and settlement calls: it uses Circle Gateway / SELAT Router nanopayments (x402, MPP on Tempo), compiles steps into selat-pay calls, and supports real "paid" runs that settle from a funded Circle Gateway balance. Those are specific payment/settlement APIs and on-chain settlements (including probe vs. --pay real settlement), so the skill can execute real financial transfers to upstream providers — i.e., direct financial execution authority.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata