linkfox-amazon-store-external-fulfillment
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该 skill 在运行时会读取用户/调用者通过脚本入参提供的 JSON(如 scripts/post_batch_inventory.py、get_shipments.py 等的 sys.argv[1]),并将其中字符串字段(例如 referenceId/lineItems/reason 等)原样编码进 developerProxy 后端请求;这些字段本身属于外部可控自由文本输入面。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata