senpi-improve-trades
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/review.py, the telemetry step shells out toopenclaw senpi events --runtime <id> --jsonfor each CURRENT (ACTIVE/PAUSED) strategy runtime and ingests the returnedentries(includingsignal.outcomefields likesenpi.outcome.reason_code/resultand any free-text-like event bodies/attrs), which can be influenced by outsider-authored runtime state/events.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata