amz-review-analyzer

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.95). The skill’s required workflow ingests “pasted reviews” (including competitor reviews) as free-form text at runtime, and those reviews are outsider-authored content provided by someone other than the operating user.

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the skill content. No API keys, PEM/private key blocks, or obvious passwords are present. However the document contains a WhatsApp invite URL (https://chat.whatsapp.com/ILX65p1yWcaIG3cW9pTY). The invite code portion is a high-entropy literal that grants access to a group (i.e., it functions as an access token), so it meets the definition of a secret here. No other high-entropy credentials or secrets were found. There were no auto-detected potential matches in the <potential_matches> section.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:08 PM
Issues
2
Security Audit — snyk — amz-review-analyzer