linkfox-shopee-store-add-on-deal

Warn

Audited by Snyk on Aug 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 skill 在运行时会把用户/调用方提供的 JSON 参数(如 shopId/merchantId 及其余字段)拼入 api/v2/add_on_deal/* 请求,并通过 POST /shopee/developerProxy 把这些输入与 Shopee 返回的 response 一并落盘/摘要输出;因此若外部用户可控制入参,就存在间接 prompt-injection 面向“外部自由文本”的数据暴露面。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 17, 2026, 07:03 AM
Issues
1
Security Audit — snyk — linkfox-shopee-store-add-on-deal