category-selection
Warn
Audited by Snyk on Aug 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 运行路径为
scripts/analyze_category.py:在_parse_sse_response()中解析从https://mcp.sorftime.com?key=...接收到的 SSEdata并json.loads(),随后在extract_and_analyze()与generate_reports()里把返回的产品标题/品牌/卖家等字段用于报告生成,因此存在外部方可通过被查询的类别/产品数据“投毒”这段免费文本的间接注入暴露面。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata