linkfox-echotik-list-product
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md’s required runtime workflow, user-supplied
keyword/filters are sent toPOST /echotik/listProductinscripts/echotik_list_product.py, and the resulting free-text fields in the API response (e.g., product names/descriptions/status texts) are then written/printed for the agent/LLM to consume.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata