recent-funding-rounds

Warn

Audited by Snyk on Jul 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The required workflow sends a user-provided sector query to Brave Search’s POST https://brave.mpp.paywithlocus.com/brave/news-search, which returns outsider-authored news article content; the skill then reads/extracts deal details from that returned article text.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly initiates on-chain/MPP payments as part of its workflow: it compiles the step into a selat-pay call and routes settlement through the SELAT Router (paying Brave Search via Locus over MPP). That is an explicit payment/transaction execution capability (the skill programmatically issues payments to settle the API call), so it grants the agent the ability to send money/transactions, not merely to query data.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 29, 2026, 07:34 PM
Issues
2
Security Audit — snyk — recent-funding-rounds