linkfox-mercado-product-selection
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Runtime path:
scripts/linkfox_mercado_product_selection.pysends user-derivedparams(includingarguments.searchText/itemIdetc.) verbatim to the backend viaPOST ${LINKFOX_TOOL_GATEWAY}/lingdong/call, then the script writes/prints the resultingdata/contentTextwithout fetching any specific first-party vetted outsider text first.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata