dividend-corporate-action-tracker

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow (references/data-queries.md and the views_runner.py commands) instructs the agent to fetch and ingest third-party public web data (e.g., 新浪财经 stock_history_dividend, 巨潮资讯/深交所 CNInfo via stock_dividend_cninfo, 东方财富 and 百度 trade_notify views) as part of analysis, so untrusted external content can directly influence tool outputs and decision rules.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:23 AM