vipshop-user-login

Warn

Audited by Snyk on Apr 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill directly calls public endpoints on https://passport.vip.com (initQrLogin, getQrImage, checkStatus) and the SKILL.md plus vip_login.py explicitly instruct the agent to extract the machine-readable JSON payload between [VIPSHOP_QR_PAYLOAD_BEGIN]/[END] (qrImageUrl/qrToken) and to read poll responses (StatusPoller.check_status) to decide next actions (display QR, poll, save cookies), so untrusted third‑party responses can materially influence the agent's behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 07:04 AM
Issues
1