vc-ai-infra-scout
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow ingests outsider-authored free text from Twitter/X and LinkedIn via SELAT-native
advanced_search(fundraising news and investor-thesis tweets) and TavilyPOST /search(LinkedIn fundraising posts), which are populated by public user submissions.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly performs paid calls and payment settlements: it states the agent "pays for the data" across named payment rails (x402 via Circle Gateway, SELAT Router, x402 on Base), compiles each step into selat-pay calls, includes a per-run
maxAmountand per-step caps, and documentsselat-payprobe and--pay(to settle real payments). These are specific payment gateways/rails and an execution CLI (selat-pay/Circle Gateway/Base) — i.e., explicit financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata