trade-compare
Warn
Audited by Snyk on May 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's SKILL.md Data Collection Phase explicitly issues WebSearch queries for each ticker and requires extracting and using information from public web pages to compute scores and drive recommendations, so untrusted third-party web content could directly influence the agent's decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata