@6522/deepresearch

Warn

Audited by Snyk on Aug 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). SKILL.md describes a quant/DeFi workflow that ingests outsider-authored text only indirectly via specific third-party data skills (e.g., social sentiment from twitter/lunarcrush and project intel from web_search/web_fetch), but it does not describe any runtime step that continuously monitors a feed/queue for arbitrary outsider submissions without first actively fetching/selecting specific content.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The SKILL.md explicitly lists exchange/account and execution integrations. It names binance-account and okx-account for account/balances/positions and lists hyperliquid and wallet as the primary tools for "Trade execution" — i.e., specific trading/account integrations capable of placing orders or managing crypto assets. Those are concrete crypto exchange/wallet execution capabilities, which meet the "Direct Financial Execution" criteria.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 08:26 PM
Issues
2
Security Audit — snyk — @6522/deepresearch