dividend-corporate-action-tracker
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflow (references/data-queries.md and the views_runner.py commands) instructs the agent to fetch and ingest third-party public web data (e.g., 新浪财经 stock_history_dividend, 巨潮资讯/深交所 CNInfo via stock_dividend_cninfo, 东方财富 and 百度 trade_notify views) as part of analysis, so untrusted external content can directly influence tool outputs and decision rules.
Audit Metadata