listing-keyword-optimizer
Warn
Audited by Snyk on Jun 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill calls NexScope proxy endpoints that return competitor product listings (e.g.,
/api/v1/tools/linkfox/amazon/searchand/api/v1/tools/linkfox/amazon/product/detail), and it then ingests competitor titles/brand fields as readable text into the LLM context viacompetitor_titles→build_product_context(... source_text_parts.append(' '.join(competitor_titles[:5])) ...)andextract_title_keywords(competitor_titles).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata