linkfox-shopee-store-logistics
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在
scripts/logistics_api.py/_logistics_api_runner.py运行时,LLM 会把用户提供的 JSON(包括api、order_sn、body等)传入run_logistics_api,再经developerProxy调用转发到https://tool-gateway.linkfox.com/shopee/developerProxy,并最终解析该响应 JSON(包含任意文本字段)用于摘要/落盘输出。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata