review-analyzer

Warn

Audited by Snyk on Jun 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.95). Outsider free text is ingested into the LLM via analyze_reviews/voc_full: the tool embeds reviews[:150] (including body/content from Shulex VOC API or user-provided CSV/URL) into the user_content JSON block sent to Claude (mcp_server/clients/analyzer.py), and those review bodies are authored by non-operating users (Amazon reviewers / CSV authors).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 4, 2026, 02:36 PM
Issues
1
Security Audit — snyk — review-analyzer