shopee
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill's scripts (scripts/shopee.py) use Camoufox to navigate to and fetch content from Shopee (https://shopee.com.br), intercept public /api/v4/* responses and parse rendered HTML (product pages, descriptions and reviews) — clearly ingesting untrusted, user-generated third-party content that the tool parses and acts on (e.g., deciding results, filtering, and outputs).
Audit Metadata