maishou

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's scripts (scripts/main.py) POST to public APIs at https://msapi.maishou88.com and https://appapi.maishou88.com to fetch product titles, shop info, purchase links and "copy commands" (商品详情/购买链接/复制口令), which are untrusted third‑party/user-generated content that the agent parses and returns and could materially influence subsequent actions (e.g., following links or using returned commands).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 09:34 AM
Issues
1
Security Audit — snyk — maishou