amazon-shopping
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly opens and snapshots public Amazon pages (see SKILL.md "Search Workflow" steps and the mandatory verification flow) and its scripts (scripts/extract_products.py and scripts/verify_products.sh) ingest and parse those third-party page snapshots to drive verification, ranking, and presentation decisions, so untrusted web content can materially influence agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata