domain-query

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In scripts/domain_query.py, the runtime ingests outsider-provided domain/--url arguments (free text) and sends them to external APIs on cn.apihz.cn (/icp.php, /whoisall.php, /wxfh.php), then parses/prints the returned text (including WHOIS raw content) back to the user.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 06:30 PM
Issues
1
Security Audit — snyk — domain-query