email-connector
Warn
Audited by Snyk on Aug 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s runtime workflow reads provider webhook events from inbound HTTP requests, parses the raw body only after signature verification, and then upserts suppression entries (app/api/email/webhook/route.ts: raw req.text() → verifyProviderSignature → JSON.parse).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata