linkfox-temu-compliance-global
Warn
Audited by Snyk on Aug 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 在
scripts/的各入口脚本中,LLM 通过用户提供的'<JSON 参数>'组装请求并在scripts/_temu_global_common.py调用POST /temu/proxy,将其网关返回的result/body(以及可能的errorMsg/msg等任意字符串字段)经emit_result()落盘并直接打印摘要/样本进入上下文;因此外部可控的“用户自由文本”(JSON 内的字符串字段)会被读取。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata