hexabot-channel-creator
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the Hexabot “channel” runtime path, outsider-authored free text is ingested from the provider webhook/request body at
HttpChannelHandler.decode()(e.g.,examples/acme-http-channel/index.channel.tsparsesreq.bodywithAcme.webhookSchema.parseand then usesrawEvent.message.text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata