asin-data-api

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill instructs the agent to connect to the ASIN Data API via the Membrane connector (e.g., membrane connect --connectorKey asin-data-api and membrane action run ...) to fetch product fields including descriptions and user reviews from Amazon, which are untrusted third-party/user-generated content that the agent is expected to read and use in its workflow.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 08:46 PM
Issues
1