linkfox-temu-tax-eu

Warn

Audited by Snyk on Aug 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Runtime workflow: the scripts (e.g., scripts/temu_eu_proxy.py calling eu_proxy_callcall_temu_api) ingest user-supplied JSON free text via CLI args (load_json_arg(sys.argv)) and then forward it as the type and params body to POST https://tool-gateway.linkfox.com/temu/proxy, with no restriction that forces selecting a specific pre-defined item before the LLM ingests the attacker text.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 17, 2026, 07:05 AM
Issues
1
Security Audit — snyk — linkfox-temu-tax-eu