send-email
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Outsider-authored text enters only via the operator-provided
${var}request (parsed in “Steps → Parse the request from${var}” and used to formPAYLOADfor the ResendPOST https://api.resend.com/emails), so the runtime does ingest freeform external text but only as explicitly provided for composing/sending.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata