store-teardown

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). Yes — the SKILL.md workflow explicitly instructs fetching and scraping public third‑party sites (e.g., taobao_fetch.py for Taobao/Tmall pages, google_images.py for Google Image Search, instagram_search.py for Instagram and arbitrary store URLs) and then parsing those HTML/JSON and downloaded images for downstream analysis (Phase 1 → Phase 2), so untrusted/user‑generated content is ingested and can materially influence the agent's analysis and actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 09:34 AM
Issues
1
Security Audit — snyk — store-teardown