bggg-data-amazon

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/amazon_review_scraper.py the runtime directly fetches and ingests free text fields (Author, Title, Text) from the Woot/Amazon reviews AJAX JSON endpoint at https://www.woot.com/review/Reviews/{ASIN} for each target ASIN, and those fields are later preserved verbatim and normalized in scripts/normalize_reviews.py.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 01:34 AM
Issues
1
Security Audit — snyk — bggg-data-amazon