linkfox-shopee-store-global-product

Warn

Audited by Snyk on Aug 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 脚本把外部传入的 JSON 参数(含任意字符串字段)直接用于构造 developerProxyqueryString/body 并调用 POST https://tool-gateway.linkfox.com/shopee/developerProxy,且会落盘与在 stdout 打印该返回内容,形成“外人可通过输入 JSON 注入任意文本并被 LLM/工具读取”的间接提示注入暴露面。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 17, 2026, 07:03 AM
Issues
1
Security Audit — snyk — linkfox-shopee-store-global-product