websocket-engineer

Warn

Audited by Snyk on Aug 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime path for outsider-provided free text is Socket.IO/WebSocket message payloads (e.g., socket.handshake.auth.token and socket.on("message", ({ roomId, text }) => ...) where text originates from connected clients), meaning an outsider can supply arbitrary text to the workflow over the socket.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:59 PM
Issues
1
Security Audit — snyk — websocket-engineer