evolution-api
Fail
Audited by Snyk on Aug 26, 2026
Risk Level: HIGH
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Evolution API’s required webhook/event delivery workflow ingests message text from the subscribed webhook/event channels (e.g.,
MESSAGES_UPSERTpayloads containingdata.message.conversation) which can be populated by outsiders sending WhatsApp messages.
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I searched the documentation for literal, high-entropy values that could be usable credentials.
Flagged:
- references/environment-variables.md:[18] contains AUTHENTICATION_API_KEY example value "429683C4C977415CAAFCCE10F7D57E11". This is a high-entropy, random-looking hex string (not an obvious placeholder like YOUR_API_KEY), so it could represent an actual API key and is therefore flagged.
Ignored (not flagged) with reasons:
- SKILL.md:[77] "generated-instance-token" — obvious placeholder/description.
- SKILL.md:[25]/[34] "YOUR_API_KEY" / "" — documentation placeholders.
- SKILL.md:[48] "optional-custom-token" — example/placeholder.
- SKILL.md:[74] instanceId GUID ("af6c5b7c-...") — an identifier, not a secret.
- references/environment-variables.md:[27]
postgresql://user:pass@localhost:5432/evolution— uses simple "user:pass" example (low-entropy placeholder). - references/environment-variables.md:[73] WA_BUSINESS_TOKEN_WEBHOOK example "evolution" — low-entropy/example value.
- Other environment examples (redis URI, S3 keys, SQS keys listed as variable names) contain either empty examples or non-sensitive example strings and were ignored as placeholders.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata