linkfox-amazon-store-external-fulfillment

Warn

Audited by Snyk on Aug 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 skill 在运行时会读取用户/调用者通过脚本入参提供的 JSON(如 scripts/post_batch_inventory.py、get_shipments.py 等的 sys.argv[1]),并将其中字符串字段(例如 referenceId/lineItems/reason 等)原样编码进 developerProxy 后端请求;这些字段本身属于外部可控自由文本输入面。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:04 PM
Issues
1
Security Audit — snyk — linkfox-amazon-store-external-fulfillment