{"root_cid":"bafybeidfxr556mi7i3mnugalnijkydgzjfusrqzh3dzh44dzpgpnioja7e","model":"openai/gpt-5.4-mini","analyzed_at":"2026-05-06T09:23:05.296Z","result":{"schema_version":1,"category":"Finance","category_confidence":0.98,"summary":"A simple financial-planning assistant page for WealthWizard loads a remote AI agent and exposes a client-side API key.","signals":["analysis-context.json: name=wealthwizardai.eth, title=WealthWizard, content_type=text/html","index.html: meta description says it is 'An investment and financial planning assistant offering tailored advice, market insights, and strategies for building and managing wealth.'","index.html: window.aiData.behaviorDesc describes personalized investment and wealth-management guidance","index.html: loads remote module script from https://aipfs.glitterprotocol.tech/agent/agent.js"],"quality":{"tier":"fair","score":0.61,"is_substantive":true,"is_redirect_only":false,"is_placeholder":false,"rationale":"The page has a clear finance-focused purpose and some app wiring, but the mounted content is only a thin HTML shell with a remote agent dependency and little local functionality."},"security":{"risk":"high","risk_score":0.87,"threat_type":"other","safe_to_list":false,"findings":[{"type":"other","severity":"high","confidence":0.99,"evidence":"index.html contains `\"apiKey\": \"sk-or-v1-0649159e514ff579449dff4e6381249e027ab7a2=c)d smof\"`, exposing what appears to be a secret/API key in client-side HTML.","file":"index.html"},{"type":"suspicious_external_script","severity":"medium","confidence":0.93,"evidence":"index.html loads `https://aipfs.glitterprotocol.tech/agent/agent.js` and `https://aipfs.glitterprotocol.tech/agent/agent.css` from an external origin.","file":"index.html"}]},"files_reviewed":["analysis-context.json","index.html","44.png"]}}
