imessage-convex-agent
Warn
Audited by Snyk on Jul 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.95). The required runtime path ingests outsider-authored free text from a third-party iMessage sender via the Sendblue webhook JSON (
content→parseSendblueInbound→processInboundprompt/agent inputs), which is then fed into the LLM (agent.generateText/replyTextprompt variable).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata