category-selection

Warn

Audited by Snyk on Aug 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 运行路径为 scripts/analyze_category.py:在 _parse_sse_response() 中解析从 https://mcp.sorftime.com?key=... 接收到的 SSE datajson.loads(),随后在 extract_and_analyze()generate_reports() 里把返回的产品标题/品牌/卖家等字段用于报告生成,因此存在外部方可通过被查询的类别/产品数据“投毒”这段免费文本的间接注入暴露面。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 06:52 AM
Issues
1
Security Audit — snyk — category-selection