amazon

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's scripts (scripts/amazon.py) explicitly fetch and parse open/public Amazon.com.br pages — including product pages and user-generated reviews — via Camoufox (see SKILL.md and the fetch_html/parse_reviews/parse_product_details calls), and that untrusted content is read and used to drive outputs, filtering, and fallback behavior, so it can indirectly influence tool decisions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 06:21 AM