@1247/vampire-attack-hl

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The required runtime workflow takes outsider-supplied --wallet input and then reads Hyperliquid fill-level data plus candle snapshots via skills/vampire-attack-hl/scripts/analyze_hl_wallet.py calling https://api.hyperliquid.xyz/info endpoints (userFillsByTime and candleSnapshot), where the returned fields (e.g., fill coin, side, px, sz, fee, builderFee, time) are free-text/JSON content originating from an external party and then used to generate the client-facing markdown.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 10:18 AM
Issues
1
Security Audit — snyk — @1247/vampire-attack-hl