evolution-api

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: HIGH
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Evolution API’s required webhook/event delivery workflow ingests message text from the subscribed webhook/event channels (e.g., MESSAGES_UPSERT payloads containing data.message.conversation) which can be populated by outsiders sending WhatsApp messages.

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I searched the documentation for literal, high-entropy values that could be usable credentials.

Flagged:

  • references/environment-variables.md:[18] contains AUTHENTICATION_API_KEY example value "429683C4C977415CAAFCCE10F7D57E11". This is a high-entropy, random-looking hex string (not an obvious placeholder like YOUR_API_KEY), so it could represent an actual API key and is therefore flagged.

Ignored (not flagged) with reasons:

  • SKILL.md:[77] "generated-instance-token" — obvious placeholder/description.
  • SKILL.md:[25]/[34] "YOUR_API_KEY" / "" — documentation placeholders.
  • SKILL.md:[48] "optional-custom-token" — example/placeholder.
  • SKILL.md:[74] instanceId GUID ("af6c5b7c-...") — an identifier, not a secret.
  • references/environment-variables.md:[27] postgresql://user:pass@localhost:5432/evolution — uses simple "user:pass" example (low-entropy placeholder).
  • references/environment-variables.md:[73] WA_BUSINESS_TOKEN_WEBHOOK example "evolution" — low-entropy/example value.
  • Other environment examples (redis URI, S3 keys, SQS keys listed as variable names) contain either empty examples or non-sensitive example strings and were ignored as placeholders.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 11:03 PM
Issues
2
Security Audit — snyk — evolution-api