financial-intel

Warn

Audited by Snyk on Jul 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). Source: user-supplied --query is passed as free-text into the Exa market news / context step (POST https://api.exa.ai/search with body.query), so outsider-authored text can steer a runtime search that ingests returned snippets/headlines for synthesis.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly integrates payment rails and settlement commands: it references Circle Gateway nanopayments, x402 settlement, the SELAT Router, and the selat-pay/selat CLI that "compiles each step into a selat-pay call" and can be run with --pay to "settle real 200s" from a "funded Circle Gateway balance." It also lists per-step monetary caps and live USD prices. These are specific payment gateway/blockchain settlement operations (not generic HTTP or browser automation), so the skill grants direct financial execution capability.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 29, 2026, 07:34 PM
Issues
2
Security Audit — snyk — financial-intel