linkfox-shopee-store-global-product
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 脚本把外部传入的 JSON 参数(含任意字符串字段)直接用于构造
developerProxy的queryString/body并调用POST https://tool-gateway.linkfox.com/shopee/developerProxy,且会落盘与在 stdout 打印该返回内容,形成“外人可通过输入 JSON 注入任意文本并被 LLM/工具读取”的间接提示注入暴露面。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata